Access Control Flaw in Mattermost Agents Plugin Exposes User Activity
CVE-2025-55074

3LOW

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
18 November 2025

What is CVE-2025-55074?

Certain versions of Mattermost, specifically the Agents plugin, exhibit inadequate enforcement of access permissions. This defect allows unauthorized users to access channel member objects, thereby discovering when other users have read specific channels. Such exposure could lead to a breach of user privacy and compromise the integrity of communications within the platform.

Affected Version(s)

Mattermost 10.11.0 <= 10.11.3

Mattermost 10.5.0 <= 10.5.11

Mattermost 11.0.0

References

CVSS V3.1

Score:
3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Juho Forsén
.
CVE-2025-55074 : Access Control Flaw in Mattermost Agents Plugin Exposes User Activity