Insecure Direct Object Reference in Mattermost Boards Plugin Enables Unauthorised Comment Deletion
Vulnerability Description
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an authenticated user with the editor role to delete comments created by other users.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12756
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- daynight
References
More from Mattermost
View All →Affected Vendor
Mattermost
View all reports →