Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://mattermost.com/security-updates |
![]() ![]() |
History
Tue, 12 Aug 2025 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mattermost
Mattermost mattermost |
|
Vendors & Products |
Mattermost
Mattermost mattermost |
Mon, 11 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 11 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create channel subscription without proper access to the channel via API call to the create channel subscription endpoint. | |
Title | Unauthorized Channel Subscription Creation in Mattermost Confluence Plugin | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Mattermost
Published: 2025-08-11T18:57:07.701Z
Updated: 2025-08-11T19:41:20.762Z
Reserved: 2025-07-28T14:30:58.333Z
Link: CVE-2025-8285

Updated: 2025-08-11T19:41:16.871Z

Status : Received
Published: 2025-08-11T19:15:30.887
Modified: 2025-08-11T19:15:30.887
Link: CVE-2025-8285

No data.