We found results for “”
CVE-2025-55070
Good to know:
Date: November 14, 2025
Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Missing Authentication for Critical Function
CWE-306Top Fix
Upgrade Version
Upgrade to version github.com/mattermost/mattermost - v11.0.0;github.com/mattermost/mattermost-server - v11.1.0;github.com/mattermost/mattermost-server - v11.1.0+incompatible;github.com/mattermost/mattermost/server/v8 - v8.0.0-20250912063506-7d8b7b5e4a60
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


