CVE-2025-41410
vulnerability analysis and mitigation

Overview

CVE-2025-41410 is a Missing Authorization vulnerability in Mattermost Server that allows attackers to create verified user accounts with arbitrary email domains by exploiting the Slack import process. Affected versions include 10.10.x ≤ 10.10.2, 10.5.x ≤ 10.5.10, and 10.11.x ≤ 10.11.2. The vulnerability was published on October 16, 2025, and received a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Mattermost Security).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): Mattermost fails to validate email ownership during the Slack workspace import process, allowing imported user records to be marked as verified without confirming actual ownership of the specified email address. An attacker with low-privilege access can craft malicious Slack import data containing arbitrary email addresses, which Mattermost then accepts as verified accounts. This bypasses email-based team access restrictions, as the platform trusts the imported email metadata without performing an ownership check (GitHub Advisory, Mattermost Security).

Impact

Successful exploitation allows an attacker with low-level access to create verified Mattermost user accounts associated with arbitrary email domains, effectively bypassing email-based team access controls. This results in limited confidentiality and integrity impacts — unauthorized users may gain access to restricted Mattermost teams or channels, and the integrity of the user authentication and verification mechanism is compromised. Availability is not impacted by this vulnerability (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (2nd percentile), indicating a low probability of exploitation in the near term. Exploitation requires low-privilege access and the ability to perform or influence a Slack import operation on the target Mattermost instance (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Mattermost instance running a vulnerable version (10.5.x ≤ 10.5.10, 10.10.x ≤ 10.10.2, or 10.11.x ≤ 10.11.2) where the attacker has at least low-privilege (authenticated) access and permission to perform Slack imports.
  2. Craft malicious Slack export data: Prepare a Slack workspace export archive (ZIP file) containing user records with arbitrary, attacker-controlled email addresses — including domains belonging to restricted teams or organizations.
  3. Initiate Slack import: Use the Mattermost admin interface or API to import the crafted Slack export data into the target Mattermost instance.
  4. Bypass email verification: Because Mattermost does not validate email ownership during import, the imported user accounts are created with their emails marked as verified, regardless of whether the attacker controls those email addresses.
  5. Access restricted teams: The newly created verified accounts can now bypass email-domain-based team access restrictions, granting unauthorized access to Mattermost teams or channels that enforce email domain allowlists (GitHub Advisory, Mattermost Security).

Indicators of compromise

  • Logs: Mattermost audit logs showing Slack import operations performed by non-administrator or unexpected user accounts; bulk user creation events correlated with import activity.
  • User Accounts: Newly created user accounts with verified email addresses belonging to domains not typically associated with the organization, especially following a Slack import event.
  • Access Patterns: User accounts accessing teams or channels restricted by email domain allowlists shortly after a Slack import operation; accounts with verified status but no corresponding email verification workflow in logs.
  • File System/API: Unexpected Slack import archive files uploaded to the Mattermost server or API calls to the import endpoint from low-privilege accounts (GitHub Advisory).

Mitigation and workarounds

Mattermost has released patched versions addressing this vulnerability: upgrade to 10.5.11, 10.10.3, or 10.11.3 or later. As interim workarounds, administrators should restrict Slack import permissions to trusted administrators only, implement additional out-of-band email verification for imported accounts, and audit existing user accounts created via Slack import for unauthorized email domains. Monitoring user account creation logs and reviewing team access controls is also recommended (Mattermost Security, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management