Authorization Vulnerability in Mattermost by Mattermost, Inc.
CVE-2025-6226
6.5MEDIUM
What is CVE-2025-6226?
Certain versions of Mattermost exhibit an authorization flaw that compromises the integrity of private channel posts. Specifically, authenticated users can exploit the vulnerability by guessing the PendingPostID of newly created posts, gaining unauthorized access to private content. This issue affects multiple versions including 10.5.x up to 10.5.6, 10.8.x up to 10.8.1, 10.7.x up to 10.7.3, and 9.11.x up to 9.11.16, enabling an unauthorized read of sensitive information that should remain confidential.
Affected Version(s)
Mattermost 10.5.0 <= 10.5.6
Mattermost 10.8.0 <= 10.8.1
Mattermost 10.7.0 <= 10.7.3