AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-12421

CRITICAL · CVSS 9.9 EPSS 0.35%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-11-27 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.9. It affects Exchange. Exploitation may require the attacker to be authenticated.

CVE
CVE-2025-12421
Severity
CRITICAL
CVSS
9.9
EPSS
0.35%
Exchange

Original NVD Description

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).

Related CVEs

Other vulnerabilities affecting the same vendor(s)