
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-41410 is a Missing Authorization vulnerability in Mattermost Server that allows attackers to create verified user accounts with arbitrary email domains by exploiting the Slack import process. Affected versions include 10.10.x ≤ 10.10.2, 10.5.x ≤ 10.5.10, and 10.11.x ≤ 10.11.2. The vulnerability was published on October 16, 2025, and received a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Mattermost Security).
The root cause is classified as CWE-862 (Missing Authorization): Mattermost fails to validate email ownership during the Slack workspace import process, allowing imported user records to be marked as verified without confirming actual ownership of the specified email address. An attacker with low-privilege access can craft malicious Slack import data containing arbitrary email addresses, which Mattermost then accepts as verified accounts. This bypasses email-based team access restrictions, as the platform trusts the imported email metadata without performing an ownership check (GitHub Advisory, Mattermost Security).
Successful exploitation allows an attacker with low-level access to create verified Mattermost user accounts associated with arbitrary email domains, effectively bypassing email-based team access controls. This results in limited confidentiality and integrity impacts — unauthorized users may gain access to restricted Mattermost teams or channels, and the integrity of the user authentication and verification mechanism is compromised. Availability is not impacted by this vulnerability (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (2nd percentile), indicating a low probability of exploitation in the near term. Exploitation requires low-privilege access and the ability to perform or influence a Slack import operation on the target Mattermost instance (GitHub Advisory).
Mattermost has released patched versions addressing this vulnerability: upgrade to 10.5.11, 10.10.3, or 10.11.3 or later. As interim workarounds, administrators should restrict Slack import permissions to trusted administrators only, implement additional out-of-band email verification for imported accounts, and audit existing user accounts created via Slack import for unauthorized email domains. Monitoring user account creation logs and reviewing team access controls is also recommended (Mattermost Security, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."