CVE-2025-55070: Mattermost Server

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events

Affected products

  • Mattermost Mattermost Server: before 11.0.0 (fixed in 11.0.0)

Published 2025-11-14. Last modified 2026-06-17.