CVE-2025-30179
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-30179 is a vulnerability affecting Mattermost versions 10.4.x up to 10.4.2, 10.3.x up to 10.3.3, and 9.11.x up to 9.11.8. This issue allows authenticated attackers to bypass Multi-Factor Authentication (MFA) protections by exploiting a flaw in certain search APIs. Attackers can carry out user searches, channel searches, or team searches without being prompted for additional verification codes, putting sensitive information at risk. This vulnerability highlights the importance of keeping Mattermost installations updated to ensure the latest security patches are applied.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mattermost Server
Affected Vendors
- Mattermost, Inc.