Improper Permission Validation in Mattermost Affects System Administrators
CVE-2025-32093

4.7MEDIUM

Key Information:

Vendor
Mattermost
Vendor
CVE Published:
14 April 2025

Summary

Certain versions of Mattermost exhibit a flaw in their permission validation system, allowing users with 'Edit Other Users' permissions to inappropriately alter the settings or attributes of system administrators. This undermines the integrity of administrative controls and could lead to unauthorized access or changes that threaten the security of the platform. Ensuring proper permission validation is essential for maintaining the safety and functionality of Mattermost environments.

Affected Version(s)

Mattermost 10.5.0 <= 10.5.1

Mattermost 10.4.0 <= 10.4.3

Mattermost 9.11.0 <= 9.11.9

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bob10x1
.