Improper Access Control in Mattermost Confluence Plugin
CVE-2025-48731

6.4MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
11 August 2025

What is CVE-2025-48731?

The Mattermost Confluence Plugin before version 1.5.0 is vulnerable due to a failure to properly check user access rights to Confluence spaces. This oversight allows unauthorized users to modify subscription settings for spaces they should not have access to, potentially leading to unauthorized changes and data exposure. Ensuring correct access control measures are in place is crucial for maintaining the security of user information and subscriptions.

Affected Version(s)

Mattermost Confluence Plugin 0 < 1.5.0

Mattermost Confluence Plugin 1.5.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lorenzo Gallegos
.
CVE-2025-48731 : Improper Access Control in Mattermost Confluence Plugin