
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13324 is a token invalidation vulnerability in Mattermost Server affecting the remote cluster invite mechanism. Mattermost versions 10.11.x ≤ 10.11.5, 10.12.x ≤ 10.12.2, and 11.0.x ≤ 11.0.4 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token. This allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actions on shared channels even after the invitation has been legitimately confirmed. It was published on December 17, 2025, with a CVSS v3.1 base score of 3.7 (Low) per NVD, though ENISA rates it 4.3 (Medium) (Mattermost Security, Red Hat CVE).
The root cause is classified as CWE-863 (Incorrect Authorization) — specifically, the failure to invalidate one-time invite tokens after they have been used to confirm a remote cluster connection. When the legacy version 1 protocol is in use, or when the confirming party omits a refreshed token in the response, the original invite token remains valid indefinitely, enabling a token replay attack. An attacker who intercepts or otherwise obtains the invite token can reuse it to authenticate as the remote cluster and issue requests against shared channels, such as adding or removing users from private channels without authorization (Mattermost Security, ENISA EUVD).
Successful exploitation allows an attacker to authenticate as a legitimate remote cluster and manipulate channel memberships on shared channels, including adding or removing users from private channels without proper authorization. The impact is limited to integrity (no confidentiality or availability impact is reported), and exploitation requires the attacker to have previously obtained a valid invite token, constraining the blast radius. Lateral movement within the Mattermost environment via unauthorized channel access is the primary risk (Mattermost Security, ENISA EUVD).
Mattermost has released patched versions addressing this vulnerability: 10.11.6, 10.12.3, and 11.0.5. Organizations should upgrade to one of these versions immediately. As additional hardening steps, administrators should review and rotate all existing remote cluster invite tokens, ensure the latest protocol version is in use (avoiding the legacy version 1 protocol), and monitor channel membership changes for anomalies (Mattermost Security, ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."