CVE-2025-55070 - Lack of MFA enforcement in WebSocket connections
CVE ID : CVE-2025-55070
Published : Nov. 14, 2025, 8:15 a.m. | 35 minutes ago
Description : Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Nov. 14, 2025, 8:15 a.m. | 35 minutes ago
Description : Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticated users to access sensitive information via WebSocket events
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...