ZeroHour

CVE-2025-55074

CVSS 3.1
3.5 low
EPSS
<1%p7
Published
()
Modified
Description

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects

Vendors
mattermost
Products
mattermost server
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.