CVE-2025-27936

Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:ms_teams:*:*:*:*:*:*:*:*

History

14 Jan 2026, 14:29

Type Values Removed Values Added
Summary
  • (es) Las versiones &lt;2.1.0 de Mattermost Plugin MSTeams y las versiones 10.5.x &lt;=10.5.1 de Mattermost Server con el complemento MS Teams habilitado no pueden realizar una comparación de tiempo constante en un secreto de webhook del complemento MSTeams, lo que permite que un atacante recupere el secreto de webhook del complemento MSTeams a través de un ataque de tiempo durante la comparación del secreto de webhook.
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
First Time Mattermost
Mattermost mattermost Server
Mattermost ms Teams
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:ms_teams:*:*:*:*:*:*:*:*

16 Apr 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-16 10:15

Updated : 2026-01-14 14:29


NVD link : CVE-2025-27936

Mitre link : CVE-2025-27936

CVE.ORG link : CVE-2025-27936


JSON object : View

Products Affected

mattermost

  • mattermost_server
  • ms_teams
CWE
CWE-208

Observable Timing Discrepancy