CVE-2025-1412: Mattermost Server

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.

Affected products

  • Mattermost Mattermost Server: from 9.11.0, before 9.11.7 (fixed in 9.11.7); from 10.4.0, before 10.4.2 (fixed in 10.4.2)

Published 2025-02-24. Last modified 2026-06-17.