CVE detail
CVE-2025-13767 — CVE-2025-13767
Published 2025-12-24 · Modified 2026-06-17 · Vendor mattermost · Product mattermost_server · Source nvd
MEDIUM
severity
CVSS-derived band
0.0017
EPSS probability
exploitation probability, 30d
6.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References