Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when the requesting user differs from the target user ID, which allows users with edit_other_users permission to activate or deactivate MFA for other users, even if those users have not set up MFA.
References
History

Wed, 16 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Apr 2025 08:00:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to enforce MFA checks in PUT /api/v4/users/user-id/mfa when the requesting user differs from the target user ID, which allows users with edit_other_users permission to activate or deactivate MFA for other users, even if those users have not set up MFA.
Title MFA Enforcement Bypass Allows Unauthorized Removal of MFA for Other Users
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 2.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-04-16T14:34:29.842Z

Reserved: 2025-04-08T07:50:19.654Z

Link: CVE-2025-27538

cve-icon Vulnrichment

Updated: 2025-04-16T14:22:58.195Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-16T08:15:14.217

Modified: 2025-04-16T13:25:37.340

Link: CVE-2025-27538

cve-icon Redhat

No data.