Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration
https://mattermost.com/security-updates
Source: Mitre, NVD
Published: 2025-09-19
Updated: 2025-09-22
Base Score: 2.1
Vector: CVSS2#AV:N/AC:H/Au:S/C:P/I:N/A:N
Severity: Low
Base Score: 3.1
Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS: 0.00025