Authentication Bypass Vulnerability in Mattermost with Jira Plugin
CVE-2025-14273

7.2HIGH

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
22 December 2025

What is CVE-2025-14273?

Mattermost versions 11.1.x, 11.0.x, 10.12.x, and 10.11.x, along with versions of the Jira plugin up to 4.4.0, suffer from a significant vulnerability where authentication rules are not adequately enforced. This flaw permits an unauthenticated attacker who knows a valid user ID to exploit the Jira plugin. By crafting specific payloads, the attacker can send both GET and POST requests to the Jira server, spoofing the user ID and injecting arbitrary issue key paths. Organizations using affected versions are urged to review their instances and apply recommended security patches to mitigate potential exploitation risks. For more details, refer to the Mattermost security updates page.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Mattermost 11.1.0

Mattermost 11.0.0 <= 11.0.5

Mattermost 10.12.0 <= 10.12.3

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Juho Forsén
.