CVE-2025-25068: Bypassing MFA Enforcement on Plugin Endpoints
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to enforce MFA on plugin endpoints, which allows authenticated attackers to bypass MFA protections via API requests to plugin-specific routes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 10.5.1 - Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 9.11.9 - Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 10.3.4 - Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 10.4.3 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 10.6.0 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 10.4.3 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 10.3.4 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 9.11.9 - Upgrade
Upgrade
mattermostto a version that resolves this vulnerability.Fixed in 10.5.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25068?
CVE-2025-25068 has a critical severity level due to the potential for attackers to bypass MFA protections.
How do I fix CVE-2025-25068?
To fix CVE-2025-25068, upgrade Mattermost to the latest version that enforces MFA on plugin endpoints.
What versions of Mattermost are affected by CVE-2025-25068?
CVE-2025-25068 affects Mattermost versions 10.4.x up to 10.4.2, 10.3.x up to 10.3.3, 9.11.x up to 9.11.8, and 10.5.x up to 10.5.0.
What type of attacks can occur due to CVE-2025-25068?
Authenticated attackers can exploit CVE-2025-25068 to bypass multi-factor authentication protections via API requests.
Is multi-factor authentication compromised in CVE-2025-25068?
Yes, CVE-2025-25068 allows attackers to bypass multi-factor authentication settings on plugin endpoints.