CVE-2025-3230

Bypass of System Admin User Deactivation Controls for Personal Access Tokens in Mattermost Server

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly invalidate personal access tokens upon user deactivation, allowing deactivated users to maintain full system access by exploiting access token validation flaws via continued usage of previously issued tokens.


We have discovered 54 live websites that are affected by CVE-2025-3230.

Run a Free Instant Scan




Affected Software

Product  Mattermost
Category Message Boards
Vulnerable Domains54 live websites (13% of Mattermost install base)
Vulnerable Versions
  • from 9.11 through 9.11.12
  • from 10.5 through 10.5.3
  • from 10.6 through 10.6.2
  • from 10.7 through 10.7
Vulnerable Versions Count8 versions ( 12% of all versions)


Common Weakness Enumeration

CWE-303 Incorrect Implementation of Authentication Algorithm



Details

  • Published - May 30, 2025
  • Updated - May 30, 2025

Credits

  • eAhmed (finder)

Website Distribution by Country

Number of websites using CVE-2025-3230
United States7 websites



Czech Republic9 websites
Germany9 websites
Russia8 websites
GB5 websites
France3 websites
Japan2 websites
Netherlands2 websites
Turkmenistan2 websites

Website Distribution by TLD

Number of websites using CVE-2025-3230
.ru18 websites
.org11 websites
.com5 websites
.de5 websites
.be1 websites
.fr1 websites
.net1 websites
.se1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-3230

Top websites that are affected by CVE-2025-3230. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.ru Russia*,***,***
*****.*************.org GB*,***,***
*******************.com Singapore**,***,***
******.*************.org GB**,***,***
*****.****.to Japan**,***,***
****.************.se Sweden**,***,***
*******.*************.org GB**,***,***
**.********.com United States**,***,***
****.*************.fm Netherlands**,***,***
*****.****.ru Czech Republic**,***,***
See full domain list

FAQ

CVE-2025-3230 is Incorrect Implementation of Authentication Algorithm in Mattermost
A total of 54 websites have been identified as vulnerable to CVE-2025-3230, based on global website indexing conducted by WebTechSurvey.
The Mattermost is affected by the CVE-2025-3230 vulnerability.
Mattermost versions up to and including 10.7 are vulnerable to CVE-2025-3230.