CVE-2025-55070
14.11.2025, 08:15
Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket eventsEnginsight
| Vendor | Product | Version |
|---|---|---|
| mattermost | mattermost_server | 𝑥 < 11.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References