Improper Permission Validation in Mattermost Affects System Administrators
CVE-2025-32093
4.7MEDIUM
Summary
Certain versions of Mattermost exhibit a flaw in their permission validation system, allowing users with 'Edit Other Users' permissions to inappropriately alter the settings or attributes of system administrators. This undermines the integrity of administrative controls and could lead to unauthorized access or changes that threaten the security of the platform. Ensuring proper permission validation is essential for maintaining the safety and functionality of Mattermost environments.
Affected Version(s)
Mattermost 10.5.0 <= 10.5.1
Mattermost 10.4.0 <= 10.4.3
Mattermost 9.11.0 <= 9.11.9
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Bob10x1