CVE-2025-13767
vulnerability analysis and mitigation

Overview

CVE-2025-13767 is an incorrect authorization vulnerability in the Mattermost Jira plugin that allows authenticated attackers to read post content and attachments from channels they are not members of. It affects Mattermost Server versions 11.1.x ≤ 11.1.0, 11.0.x ≤ 11.0.5, 10.12.x ≤ 10.12.3, and 10.11.x ≤ 10.11.7. The vulnerability was published on December 24, 2025, with patches released the same day. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Red Hat).

Technical details

The root cause is a failure to validate user channel membership (CWE-863: Incorrect Authorization) when the Mattermost Jira plugin processes requests to attach Mattermost posts as comments to Jira issues. An authenticated attacker with access to the Jira plugin can reference post IDs from channels they are not authorized to access, and the plugin will retrieve and expose the post content and attachments without verifying the requester's channel membership. Exploitation requires only low-level authenticated access to the Mattermost instance with the Jira plugin enabled, and no user interaction is needed. The fix was committed in the Mattermost repository at commit b57c297 (GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker to read confidential post content and file attachments from private or restricted Mattermost channels they are not authorized to access, breaking the platform's channel-based access control model. The impact is limited to confidentiality — there is no integrity or availability impact. Sensitive business communications, shared files, or credentials posted in private channels could be exposed to unauthorized internal users (GitHub Advisory, Red Hat).

Exploitation steps

  1. Identify target: Confirm the target Mattermost instance is running a vulnerable version (11.1.0, ≤11.0.5, ≤10.12.3, or ≤10.11.7) with the Jira plugin enabled.
  2. Authenticate: Log in to the Mattermost instance with any valid low-privileged user account that has access to the Jira plugin.
  3. Enumerate post IDs: Identify or enumerate post IDs from channels the attacker does not have membership in (e.g., through guessing, leaked references, or other information disclosure).
  4. Attach post to Jira issue: Use the Jira plugin's "attach post as comment" functionality, supplying the target post ID from the restricted channel.
  5. Read unauthorized content: The plugin retrieves and attaches the post content and any file attachments without validating channel membership, exposing the restricted data to the attacker (GitHub Advisory).

Indicators of compromise

  • Logs: Mattermost server logs showing Jira plugin API calls referencing post IDs from channels the requesting user is not a member of; unusual cross-channel post attachment activity in audit logs.
  • Behavioral: A single user account making repeated Jira plugin requests to attach posts from multiple different channels, especially channels they have no visible membership in.
  • Application: Jira issues receiving comments with Mattermost post content from channels that the Jira-linked Mattermost user should not have access to.

Mitigation and workarounds

Mattermost has released patched versions addressing this vulnerability: 11.1.1, 11.0.6, 10.12.4, and 10.11.8. Organizations should upgrade to one of these versions immediately. As a temporary workaround if patching is not immediately possible, administrators should restrict Jira plugin access to only trusted users, or disable the Jira integration entirely until the patch can be applied. Reviewing channel access logs for anomalous cross-channel post attachment activity is also recommended (GitHub Advisory, Mattermost Security).

Community reactions

The vulnerability received limited public attention given its moderate severity rating. It was noted on Bluesky via automated CVE tracking accounts shortly after disclosure. A brief technical write-up was published by Infinit Security covering the unauthorized read access issue. Red Hat also tracked the CVE for their product ecosystem (Red Hat).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management