CVE-2025-2571

EUVD-2025-16490
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.2 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
MattermostCNA
4.2 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
Affected Products (NVD)
VendorProductVersion
mattermostmattermost_server
9.11.0 ≤
𝑥
< 9.11.13
mattermostmattermost_server
10.5.0 ≤
𝑥
< 10.5.4
mattermostmattermost_server
10.6.0 ≤
𝑥
< 10.6.3
mattermostmattermost_server
10.7.0 ≤
𝑥
< 10.7.1
𝑥
= Vulnerable software versions