CVE-2025-13324
vulnerability analysis and mitigation

Overview

CVE-2025-13324 is a token invalidation vulnerability in Mattermost Server affecting the remote cluster invite mechanism. Mattermost versions 10.11.x ≤ 10.11.5, 10.12.x ≤ 10.12.2, and 11.0.x ≤ 11.0.4 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token. This allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actions on shared channels even after the invitation has been legitimately confirmed. It was published on December 17, 2025, with a CVSS v3.1 base score of 3.7 (Low) per NVD, though ENISA rates it 4.3 (Medium) (Mattermost Security, Red Hat CVE).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization) — specifically, the failure to invalidate one-time invite tokens after they have been used to confirm a remote cluster connection. When the legacy version 1 protocol is in use, or when the confirming party omits a refreshed token in the response, the original invite token remains valid indefinitely, enabling a token replay attack. An attacker who intercepts or otherwise obtains the invite token can reuse it to authenticate as the remote cluster and issue requests against shared channels, such as adding or removing users from private channels without authorization (Mattermost Security, ENISA EUVD).

Impact

Successful exploitation allows an attacker to authenticate as a legitimate remote cluster and manipulate channel memberships on shared channels, including adding or removing users from private channels without proper authorization. The impact is limited to integrity (no confidentiality or availability impact is reported), and exploitation requires the attacker to have previously obtained a valid invite token, constraining the blast radius. Lateral movement within the Mattermost environment via unauthorized channel access is the primary risk (Mattermost Security, ENISA EUVD).

Exploitation steps

  1. Token Acquisition: Obtain a valid Mattermost remote cluster invite token through network interception, insider access, or exposure in logs/configuration files before or during the cluster invitation process.
  2. Identify Legacy Protocol Usage: Confirm that the target Mattermost instance uses the legacy version 1 remote cluster protocol, or that the confirming party did not supply a refreshed token upon accepting the invitation.
  3. Replay the Token: Craft an API request to the Mattermost remote cluster endpoint, supplying the previously obtained invite token to authenticate as the remote cluster.
  4. Manipulate Shared Channels: Once authenticated as the remote cluster, issue requests to add or remove users from private or shared channels, bypassing normal authorization controls (Mattermost Security, ENISA EUVD).

Indicators of compromise

  • Logs: Mattermost server logs showing remote cluster authentication events using tokens that were previously used to confirm an invitation; repeated or unexpected remote cluster API calls after a cluster invitation was already confirmed.
  • Network: Unexpected inbound API requests to Mattermost remote cluster endpoints from unknown or unauthorized IP addresses, particularly using invite tokens.
  • Application: Unexplained changes to channel membership in shared or private channels, such as users being added or removed without corresponding admin actions (Mattermost Security).

Mitigation and workarounds

Mattermost has released patched versions addressing this vulnerability: 10.11.6, 10.12.3, and 11.0.5. Organizations should upgrade to one of these versions immediately. As additional hardening steps, administrators should review and rotate all existing remote cluster invite tokens, ensure the latest protocol version is in use (avoiding the legacy version 1 protocol), and monitor channel membership changes for anomalies (Mattermost Security, ENISA EUVD).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management