PT-2025-46947 · Mattermost · Mattermost
CVE-2025-55070
·
Published
2025-10-15
·
Updated
2026-07-30
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mattermost versions prior to 11
Description
Mattermost versions before 11 do not enforce multi-factor authentication on WebSocket connections. This allows unauthenticated users to access sensitive information through WebSocket events.
Recommendations
Update to a version of Mattermost that is version 11 or later.
Fix
DoS
Improper Access Control
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mattermost