
We found results for “”
CVE-2025-6226
Good to know:

Date: July 18, 2025
Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the PendingPostID of recently created posts.
Severity Score
Related Resources (6)
Severity Score
Weakness Type (CWE)
Missing Authentication for Critical Function
CWE-306Top Fix

Upgrade Version
Upgrade to version github.com/mattermost/mattermost - v9.11.17;github.com/mattermost/mattermost - v10.5.7;github.com/mattermost/mattermost - v10.7.4;github.com/mattermost/mattermost - v10.8.2
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |