Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the "Edit Other Users" permission to perform unauthorized modifications to system administrators via improper permission validation.
CVE ID: CVE-2025-32093
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.7
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Vendor: Mattermost
Product: Mattermost
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.97% (scored less or equal to compared to others)
EPSS Date: 2025-04-20 (when was this score calculated)