Mattermost fails to validate user permissions when deleting comments in Boards
Moderate severity
GitHub Reviewed
Published
Dec 1, 2025
to the GitHub Advisory Database
•
Updated Dec 2, 2025
Description
Published by the National Vulnerability Database
Dec 1, 2025
Published to the GitHub Advisory Database
Dec 1, 2025
Reviewed
Dec 2, 2025
Last updated
Dec 2, 2025
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate user permissions when deleting comments in Boards, which allows an authenticated user with the editor role to delete comments created by other users.
References