Mattermost Search API Vulnerability Allowing MFA Bypass

Vulnerability

A vulnerability exists in Mattermost versions 10.4.x through 10.4.2, 10.3.x through 10.3.3, and 9.11.x through 9.11.8, where multi-factor authentication (MFA) is not properly enforced on certain search APIs. This flaw enables authenticated attackers to bypass MFA protections by exploiting user search, channel search, or team search queries.

Impact

Exploitation of this vulnerability allows authenticated attackers to bypass multi-factor authentication protections on specific search APIs, potentially leading to unauthorized access or actions that require MFA.

Remediation

Users can upgrade to Mattermost versions 10.9.0, 10.8.0, 10.7.0, 10.6.0, or 9.11.0 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
5.0
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.