{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-06T09:53:54.468","vulnerabilities":[{"cve":{"id":"CVE-2025-6226","sourceIdentifier":"responsibledisclosure@mattermost.com","published":"2025-07-18T09:15:26.993","lastModified":"2025-10-02T19:49:18.610","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the PendingPostID of recently created posts."},{"lang":"es","value":"Las versiones de Mattermost 10.5.x &lt;= 10.5.6, 10.8.x &lt;= 10.8.1, 10.7.x &lt;= 10.7.3, 9.11.x &lt;= 9.11.16 no pueden verificar la autorización al recuperar publicaciones en caché mediante PendingPostID, lo que permite que un usuario autenticado lea publicaciones en canales privados a los que no tiene acceso al adivinar el PendingPostID de publicaciones creadas recientemente."}],"metrics":{"cvssMetricV31":[{"source":"responsibledisclosure@mattermost.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"responsibledisclosure@mattermost.com","type":"Secondary","description":[{"lang":"en","value":"CWE-306"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*","versionStartIncluding":"9.11.0","versionEndExcluding":"9.11.17","matchCriteriaId":"3F117291-CF45-4790-8BEB-E51DB0BAEF82"},{"vulnerable":true,"criteria":"cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*","versionStartIncluding":"10.5.0","versionEndExcluding":"10.5.7","matchCriteriaId":"C91210B2-4844-4928-9AE6-086E1C55AACB"},{"vulnerable":true,"criteria":"cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*","versionStartIncluding":"10.7.0","versionEndExcluding":"10.7.4","matchCriteriaId":"16C5891E-6981-4903-A57E-A7AF4FDE2D1B"},{"vulnerable":true,"criteria":"cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*","versionStartIncluding":"10.8.0","versionEndExcluding":"10.8.2","matchCriteriaId":"7B0956AE-D67B-4FC3-98A8-67DD6904A90F"}]}]}],"references":[{"url":"https://mattermost.com/security-updates","source":"responsibledisclosure@mattermost.com","tags":["Vendor Advisory"]}]}}]}