We found results for “”
CVE-2025-12419
Good to know:
Date: November 27, 2025
Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authentication data during the OAuth completion flow. This requires email verification to be disabled (default: disabled), OAuth/OpenID Connect to be enabled, and the attacker to control two users in the SSO system with one of them never having logged into Mattermost.
Severity Score
Related Resources (10)
Severity Score
Weakness Type (CWE)
Top Fix
Upgrade Version
Upgrade to version github.com/mattermost/mattermost - v10.5.13;github.com/mattermost/mattermost - v10.11.5;github.com/mattermost/mattermost - v10.12.2;github.com/mattermost/mattermost - v11.0.4;github.com/mattermost/mattermost/server/v8 - v8.0.0-20251028000919-d3ed703dc833;github.com/mattermost/mattermost-server - v10.12.2;github.com/mattermost/mattermost-server - v10.11.5;github.com/mattermost/mattermost-server - v10.5.13;github.com/mattermost/mattermost-server - v11.0.4
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


