CVE-2025-14273HIGH 8.3EPSS p13.3%

CVE-2025-14273CVE-2025-14273

Description

Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the Jira plugin, which allows an unauthenticated attacker who knows a valid user ID to issue authenticated GET and POST requests to the Jira server via crafted plugin payloads that spoof the user ID and inject arbitrary issue key paths. Mattermost Advisory ID: MMSA-2025-00555

Scoring

CVSS 3.18.3 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
EPSS0.23% probability of exploitation · percentile 13.3% · 2026-06-19T12:03:05Z
Published2025-12-22
Last modified2025-12-29

Underlying weaknesses· 1

CWE-303

References

  1. https://mattermost.com/security-updates

1

TypeTargetConfidenceTier
WeaknessIncorrect Implementation of Authentication Algorithmcwe-3030%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-4858
CVE
CVE-2026-28741
CVE
CVE-2025-58073
CVE
CVE-2025-25068
CVE
CVE-2026-3116
CVE
CVE-2026-3524
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.