We found results for “”
CVE-2025-9081
Good to know:
Date: September 19, 2025
Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration
Severity Score
Related Resources (8)
Severity Score
Weakness Type (CWE)
Authorization Bypass Through User-Controlled Key
CWE-639Top Fix
Upgrade Version
Upgrade to version github.com/mattermost/mattermost - v9.11.18;github.com/mattermost/mattermost - v10.5.9;github.com/mattermost/mattermost-plugin-boards - v0.0.0-20250716054606-3f3e3becfe1d;github.com/mattermost/mattermost/server/v8 - v8.0.0-20250721095935-11c36f4d1e44;github.com/mattermost/mattermost-server - v9.11.18+incompatible
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | LOW |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | NONE |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


