Mattermost Confluence Plugin Access Control Vulnerability in Subscription Editing

Vulnerability

A vulnerability exists in the Mattermost Confluence Plugin, specifically in versions prior to 1.5.0. The issue arises because the plugin fails to properly verify user access to Confluence spaces. This oversight allows attackers to manipulate subscriptions for spaces they do not have permission to access, by exploiting the edit subscription endpoint.

Impact

Exploitation of this vulnerability could lead to unauthorized modification of Confluence space subscriptions, allowing attackers to interfere with subscription management processes.

Remediation

Users can upgrade to Mattermost Confluence Plugin version 1.5.0 or later to address this vulnerability.

Added: Aug 11, 2025, 7:42 PM
Updated: Aug 11, 2025, 7:42 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.2
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.