CVE-2025-58073HIGH 8.1EPSS p29.6%

CVE-2025-58073CVE-2025-58073

Description

Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the OAuth state.

Scoring

CVSS 3.18.1 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS0.38% probability of exploitation · percentile 29.6% · 2026-06-18T12:00:27Z
Published2025-10-16
Last modified2025-10-21

Underlying weaknesses· 1

CWE-862

References

  1. https://mattermost.com/security-updates

1

TypeTargetConfidenceTier
WeaknessMissing Authorizationcwe-8620%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-58075
CVE
CVE-2025-12419
CVE
CVE-2025-25068
CVE
CVE-2025-14273
CVE
CVE-2025-12421
CVE
CVE-2026-28741
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.