CVE-2025-31947
Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to lockout LDAP users following repeated login failures, which allows attackers to lock external LDAP accounts through repeated login failures through Mattermost.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L
- EPSS probability
- 0.34%
- CWE
- CWE-645
- Published
- 2025-05-15
- Last modified
- 2026-03-12
Affected products
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
Weakness type
Related vulnerabilities
- CVE-2026-53982 — Cap-go Console < 12.28.2 Account Deletion DoS via Device Identifier Association
- CVE-2026-25907 — Dell PowerScale OneFS, version 9.13.0.0, contains an overly restrictive account lockout mechanism...
- CVE-2025-5241 — Denial-of-Service Vulnerability in MELSEC iQ-F Series
- CVE-2024-37028 — BIG-IP Next Central Manager vulnerability
- CVE-2024-1722 — Keycloak-core: dos via account lockout
- CVE-2023-4346