{"id":"CVE-2025-55070","aliases":["GO-2025-4128"],"url":"https://o3.security/vulnerability/CVE-2025-55070","summary":"Mattermost does not enforce MFA on WebSocket connections","details":"Mattermost versions < 11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events.","published":"2025-11-14T09:30:27Z","modified":"2025-11-17T19:58:36.335728Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/mattermost/mattermost-server","fixedVersion":"11.1.0"},{"ecosystem":"Go","name":"github.com/mattermost/mattermost/server/v8","fixedVersion":"8.0.0-20250912063506-7d8b7b5e4a60"}],"fix":{"url":"https://github.com/mattermost/mattermost/commit/7d8b7b5e4a6076b2f7c87606883c417f9a610df5","label":"mattermost/mattermost@7d8b7b5"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55070"},{"type":"WEB","url":"https://github.com/mattermost/mattermost/commit/7d8b7b5e4a6076b2f7c87606883c417f9a610df5"},{"type":"PACKAGE","url":"https://github.com/mattermost/mattermost"},{"type":"WEB","url":"https://mattermost.com/security-updates"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-11-17T19:58:36.335728Z"}}