CVE-2025-9081
19.09.2025, 20:15
Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumerationEnginsight
| Vendor | Product | Version |
|---|---|---|
| mattermost | mattermost_server | 9.11.0 ≤ 𝑥 < 9.11.17 |
| mattermost | mattermost_server | 10.5.0 ≤ 𝑥 < 10.5.9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References