Improper Permission Validation in Mattermost Affects System Administrators
CVE-2025-32093
What is CVE-2025-32093?
Certain versions of Mattermost exhibit a flaw in their permission validation system, allowing users with 'Edit Other Users' permissions to inappropriately alter the settings or attributes of system administrators. This undermines the integrity of administrative controls and could lead to unauthorized access or changes that threaten the security of the platform. Ensuring proper permission validation is essential for maintaining the safety and functionality of Mattermost environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mattermost 10.5.0 <= 10.5.1
Mattermost 10.4.0 <= 10.4.3
Mattermost 9.11.0 <= 9.11.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved