CVE-2025-12419: Account takeover on OAuth/OpenID-enabled servers
Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authentication data during the OAuth completion flow. This requires email verification to be disabled (default: disabled), OAuth/OpenID Connect to be enabled, and the attacker to control two users in the SSO system with one of them never having logged into Mattermost.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12419?
CVE-2025-12419 is considered a high severity vulnerability due to its potential impact on user account security.
How do I fix CVE-2025-12419?
To fix CVE-2025-12419, update Mattermost to versions 10.12.2, 10.11.5, 10.5.13, or 11.0.4 or later.
What does CVE-2025-12419 affect?
CVE-2025-12419 affects Mattermost versions 10.12.x up to 10.12.1, 10.11.x up to 10.11.4, 10.5.x up to 10.5.12, and 11.0.x up to 11.0.3.
Who is at risk due to CVE-2025-12419?
Authenticated users with team creation or admin privileges are at risk of being able to take over any user account due to CVE-2025-12419.
What is the nature of CVE-2025-12419?
CVE-2025-12419 is a vulnerability related to improper validation of OAuth state tokens during OpenID Connect authentication.