Warning: Critical Account Takeover in Mattermost, Patch Immediately!
ID: 3fe888cd-8d41-5bbf-9a5e-21abb4dbd79d
STIX ID: report--3fe888cd-8d41-5bbf-9a5e-21abb4dbd79d
Feed Name: CCB Advisories Feed
**Executive Summary:** Two critical vulnerabilities in Mattermost (CVE-2025-12419 and CVE-2025-12421) affecting multiple 10.x and 11.0.x releases allow authenticated attackers with specific privileges to bypass OAuth/OpenID Connect checks and perform full account takeover (including administrators); both are rated CVSS 9.9. The Centre for Cybersecurity Belgium recommends immediate patching, enhanced monitoring/detection, and incident reporting, noting that patching does not remediate historic compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
