CVE 6.5 MEDIUM

IDOR in CreatePost API allows for timeboxed message disclosure_CVE-2025-6226

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Description

Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the PendingPostID of recently created posts.

Basic Information

ID CVE-2025-6226
Source Mattermost
Published Jul 18, 2025 at 08:48
Modified Aug 7, 2025 at 09:53

Affected Product

Vendor Mattermost
Product Mattermost
Version 10.5.0
Affected Versions Mattermost Mattermost 10.5.0
Mattermost Mattermost 10.8.0
Mattermost Mattermost 10.7.0
Mattermost Mattermost 9.11.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.