Mattermost Confluence Plugin Channel Subscription Access Control Vulnerability

Vulnerability

A vulnerability exists in the Mattermost Confluence Plugin versions prior to 1.5.0, where the plugin fails to properly verify user access to channels. This oversight allows attackers to create channel subscriptions via an API call to the create channel subscription endpoint, even without the necessary permissions for the channel.

Impact

Exploitation of this vulnerability allows for unauthorized channel subscriptions to be created, potentially leading to unauthorized access to channel content and interactions.

Remediation

Users can upgrade to Mattermost Confluence Plugin version 1.5.0 or later to address this vulnerability.

Added: Aug 11, 2025, 7:50 PM
Updated: Aug 11, 2025, 7:50 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.2
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.