Mattermost Cache Invalidation Vulnerability Allowing Unauthorized Bot Login

Vulnerability

A vulnerability exists in Mattermost versions 10.5.x through 10.5.1, 10.4.x through 10.4.3, and 9.11.x through 9.11.9, where the application fails to properly invalidate the cache when a user account is converted to a bot. This flaw enables an attacker to log in to the bot account once using normal credentials.

Impact

Exploitation of this vulnerability allows for unauthorized access to a bot account, enabling a one-time login using the account's regular credentials.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
1.3
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.