Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actions on shared channels even after the invitation has been legitimately confirmed.
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
29 Dec 2025, 18:46
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| References | () https://mattermost.com/security-updates - Vendor Advisory | |
| First Time |
Mattermost
Mattermost mattermost Server |
24 Dec 2025, 11:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actions on shared channels even after the invitation has been legitimately confirmed. | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.7 |
17 Dec 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-17 19:16
Updated : 2025-12-29 18:46
NVD link : CVE-2025-13324
Mitre link : CVE-2025-13324
CVE.ORG link : CVE-2025-13324
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-863
Incorrect Authorization
