{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-6226","assignerOrgId":"9302f53e-dde5-4bf3-b2f2-a83f91ac0eee","state":"PUBLISHED","assignerShortName":"Mattermost","dateReserved":"2025-06-18T10:41:12.541Z","datePublished":"2025-07-18T08:48:02.717Z","dateUpdated":"2025-08-07T09:53:06.698Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Mattermost","vendor":"Mattermost","versions":[{"lessThanOrEqual":"10.5.6","status":"affected","version":"10.5.0","versionType":"semver"},{"lessThanOrEqual":"10.8.1","status":"affected","version":"10.8.0","versionType":"semver"},{"lessThanOrEqual":"10.7.3","status":"affected","version":"10.7.0","versionType":"semver"},{"lessThanOrEqual":"9.11.16","status":"affected","version":"9.11.0","versionType":"semver"},{"version":"10.9.0","status":"unaffected"},{"version":"10.5.8","status":"unaffected"},{"version":"10.8.2","status":"unaffected"},{"version":"10.7.4","status":"unaffected"},{"version":"9.11.17","status":"unaffected"}]}],"credits":[{"lang":"en","type":"finder","value":"Dawid Kulikowski (daw10)"}],"descriptions":[{"lang":"en","value":"Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the PendingPostID of recently created posts."}],"metrics":[{"cvssV3_1":{"attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseSeverity":"MEDIUM","baseScore":6.5},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"lang":"en","type":"CWE","description":"CWE-306: Missing Authentication for Critical Function","cweId":"CWE-306"}]}],"references":[{"url":"https://mattermost.com/security-updates"}],"solutions":[{"value":"Update Mattermost to versions 10.9.0, 10.5.7, 10.8.2, 10.7.4, 9.11.17 or higher.","lang":"en"}],"source":{"advisory":"MMSA-2025-00490","defect":["https://mattermost.atlassian.net/browse/MM-64225"],"discovery":"EXTERNAL"},"title":"IDOR in CreatePost API allows for timeboxed message disclosure","providerMetadata":{"orgId":"9302f53e-dde5-4bf3-b2f2-a83f91ac0eee","shortName":"Mattermost","dateUpdated":"2025-08-07T09:53:06.698Z"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-07-18T12:39:46.280328Z","id":"CVE-2025-6226","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-07-18T12:46:21.941Z"}}]}}