Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens.
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
15 Oct 2025, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://mattermost.com/security-updates - Vendor Advisory | |
| CPE | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Summary |
|
|
| First Time |
Mattermost mattermost Server
Mattermost |
30 May 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-05-30 15:15
Updated : 2025-10-15 14:16
NVD link : CVE-2025-3230
Mitre link : CVE-2025-3230
CVE.ORG link : CVE-2025-3230
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-303
Incorrect Implementation of Authentication Algorithm
