CVE-2025-25068
vulnerability analysis and mitigation

Overview

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, and 10.5.x <= 10.5.0 contain a vulnerability that fails to enforce Multi-Factor Authentication (MFA) on plugin endpoints. This security issue was disclosed on March 21, 2025, and allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes (NVD).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 7.5 (HIGH) by Mattermost, Inc., with a vector string of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H. The NVD has assigned a slightly higher CVSS score of 8.8 (HIGH) with vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The vulnerability is classified as CWE-306 (Missing Authentication for Critical Function) (NVD).

Impact

The vulnerability allows authenticated attackers to bypass MFA protections, potentially gaining unauthorized access to protected functionality and sensitive data through plugin-specific routes. This could lead to a significant compromise of system security as it affects multiple versions of the Mattermost platform (NVD).

Mitigation and workarounds

Users should upgrade to the following fixed versions: 10.4.3 for 10.4.x users, 10.3.4 for 10.3.x users, 9.11.9 for 9.11.x users, and 10.5.1 for 10.5.x users (NVD, Mattermost).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management