Mattermost does not enforce MFA on WebSocket connections
Moderate severity
GitHub Reviewed
Published
Nov 14, 2025
to the GitHub Advisory Database
•
Updated Nov 17, 2025
Description
Published by the National Vulnerability Database
Nov 14, 2025
Published to the GitHub Advisory Database
Nov 14, 2025
Reviewed
Nov 17, 2025
Last updated
Nov 17, 2025
Mattermost versions < 11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events.
References