
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14273 is an authentication bypass vulnerability in the Mattermost Jira plugin that allows unauthenticated attackers to spoof user IDs and issue authenticated requests to a connected Jira server. It affects Mattermost Server versions 10.11.x ≤ 10.11.7, 10.12.x ≤ 10.12.3, 11.0.x ≤ 11.0.5, and 11.1.x ≤ 11.1.0 when the Jira plugin is enabled, as well as Mattermost Jira plugin versions ≤ 4.4.0. The vulnerability was disclosed on December 22, 2025, under Mattermost Advisory ID MMSA-2025-00555. It carries a CVSS v3.1 base score of 8.3 (High) per NVD, and 7.2 (High) per Mattermost (Mattermost Advisory, Red Hat CVE).
The root cause is classified as CWE-303 (Incorrect Implementation of Authentication Algorithm): the Jira plugin fails to enforce both authentication checks and issue-key path restrictions when processing plugin payloads. An unauthenticated attacker who knows a valid Mattermost user ID can craft plugin payloads that spoof that user ID and inject arbitrary Jira issue key paths, causing the plugin to forward authenticated GET and POST requests to the Jira server on behalf of the spoofed user. No prior authentication or user interaction is required, and the attack is conducted entirely over the network (Mattermost Advisory, Red Hat CVE).
Successful exploitation allows an unauthenticated attacker to perform authenticated actions against the integrated Jira server, including reading sensitive Jira issue data, modifying issues, and potentially triggering other Jira API operations that would normally require valid credentials. The vulnerability crosses scope boundaries (S:C in CVSS), meaning the impact extends beyond the Mattermost instance to the connected Jira environment. Confidentiality, integrity, and availability of Jira data are all affected, with the risk of unauthorized data disclosure and unauthorized modification of project management data (Feedly).
Mattermost has released patched versions addressing this vulnerability: update Mattermost Server to 10.11.8 or later, 10.12.4 or later, 11.0.6 or later, or 11.1.1 or later. The Mattermost Jira plugin must also be updated to version 4.4.1 or later. If immediate patching is not feasible, disabling the Jira plugin entirely is the recommended interim workaround. After patching, administrators should review Jira and Mattermost access logs for any suspicious unauthenticated activity during the exposure window (Mattermost Advisory, Red Hat CVE).
The vulnerability received coverage in security news aggregators and vulnerability tracking services shortly after disclosure on December 22, 2025. A technical write-up was published by Infinit Security describing the flaw as "Jira Request Forgery" via user ID spoofing. The CISA vulnerability bulletin for the week of December 22, 2025 included this CVE. No major vendor statements beyond Mattermost's own advisory or notable researcher controversy have been identified (CISA Bulletin, Infinit Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."