Access Control Vulnerability in Mattermost Products
CVE-2025-9081
3.1LOW
What is CVE-2025-9081?
Mattermost versions 10.5.x up to 10.5.8 and 9.11.x up to 9.11.17 are susceptible to an access control misconfiguration. This vulnerability allows authenticated users to exploit the board file download endpoint, resulting in the ability to download sensitive files through UUID enumeration. It highlights the necessity for rigorous access control validation in software to prevent unauthorized information disclosure.
Affected Version(s)
Mattermost 10.5.0 <= 10.5.8
Mattermost 9.11.0 <= 9.11.17
Mattermost 10.11.0