CVE-2025-58075
BaseFortify
Publication date: 2025-10-16
Last updated on: 2025-10-21
Assigner: Mattermost, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mattermost | mattermost_server | From 10.5.0 (inc) to 10.5.11 (exc) |
| mattermost | mattermost_server | From 10.10.0 (inc) to 10.10.3 (exc) |
| mattermost | mattermost_server | From 10.11.0 (inc) to 10.11.3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in certain versions of Mattermost where the system fails to verify if a user has permission to join a team when using the original invite token. This flaw allows an attacker to manipulate the RelayState parameter to join any team on a Mattermost server regardless of the intended access restrictions.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability can gain unauthorized access to any team on a Mattermost server, potentially exposing sensitive information and communications within those teams. This can lead to confidentiality breaches and unauthorized information disclosure.