
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13767 is an incorrect authorization vulnerability in the Mattermost Jira plugin that allows authenticated attackers to read post content and attachments from channels they are not members of. It affects Mattermost Server versions 11.1.x ≤ 11.1.0, 11.0.x ≤ 11.0.5, 10.12.x ≤ 10.12.3, and 10.11.x ≤ 10.11.7. The vulnerability was published on December 24, 2025, with patches released the same day. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Red Hat).
The root cause is a failure to validate user channel membership (CWE-863: Incorrect Authorization) when the Mattermost Jira plugin processes requests to attach Mattermost posts as comments to Jira issues. An authenticated attacker with access to the Jira plugin can reference post IDs from channels they are not authorized to access, and the plugin will retrieve and expose the post content and attachments without verifying the requester's channel membership. Exploitation requires only low-level authenticated access to the Mattermost instance with the Jira plugin enabled, and no user interaction is needed. The fix was committed in the Mattermost repository at commit b57c297 (GitHub Advisory).
Successful exploitation allows an authenticated attacker to read confidential post content and file attachments from private or restricted Mattermost channels they are not authorized to access, breaking the platform's channel-based access control model. The impact is limited to confidentiality — there is no integrity or availability impact. Sensitive business communications, shared files, or credentials posted in private channels could be exposed to unauthorized internal users (GitHub Advisory, Red Hat).
Mattermost has released patched versions addressing this vulnerability: 11.1.1, 11.0.6, 10.12.4, and 10.11.8. Organizations should upgrade to one of these versions immediately. As a temporary workaround if patching is not immediately possible, administrators should restrict Jira plugin access to only trusted users, or disable the Jira integration entirely until the patch can be applied. Reviewing channel access logs for anomalous cross-channel post attachment activity is also recommended (GitHub Advisory, Mattermost Security).
The vulnerability received limited public attention given its moderate severity rating. It was noted on Bluesky via automated CVE tracking accounts shortly after disclosure. A brief technical write-up was published by Infinit Security covering the unauthorized read access issue. Red Hat also tracked the CVE for their product ecosystem (Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."