MEDIUM 4.3 Go
Mattermost Fails to Enforce Certain Search APIs
GHSA-3gpx-p63p-pr5r · BIT-mattermost-2025-30179 · CVE-2025-30179 · GO-2025-3549
Published · Modified
Description
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to enforce MFA on certain search APIs, which allows authenticated attackers to bypass MFA protections via user search, channel search, or team search queries.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes