Mattermost LDAP User Lockout Vulnerability Allowing Account Lockout via Repeated Login Failures

Vulnerability

A vulnerability exists in Mattermost versions 10.6.x through 10.6.1, 10.5.x through 10.5.2, 10.4.x through 10.4.4, and 9.11.x through 9.11.11. These versions fail to properly lock out LDAP users after multiple failed login attempts. This oversight enables attackers to lock external LDAP accounts by exploiting the repeated login failure mechanism in Mattermost.

Impact

Exploitation of this vulnerability can lead to unauthorized lockout of LDAP accounts, causing disruption of access for affected users.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.