CVE-2025-2571: Google OAuth Authentication Bypass for Converted Bot Accounts
Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2571?
CVE-2025-2571 has a medium severity rating due to its impact on unauthorized access to bot accounts.
How do I fix CVE-2025-2571?
To fix CVE-2025-2571, upgrade Mattermost to a version that is higher than the vulnerable versions listed.
What versions of Mattermost are affected by CVE-2025-2571?
CVE-2025-2571 affects Mattermost versions 10.7.0 and below, 10.6.2 and below, 10.5.3 and below, and 9.11.12 and below.
What is the impact of CVE-2025-2571?
The impact of CVE-2025-2571 is the potential for attackers to gain unauthorized access to bot accounts through Google OAuth.
Is there a workaround for CVE-2025-2571?
There are no specific workarounds for CVE-2025-2571; upgrading to a secure version is recommended.