Loading
Generated remediation guidance and an executive summary. No account required.
Mattermost Confluence Plugin version <1.5.0 fails to enforce authentication of the user to the Mattermost instance which allows unauthenticated attackers to edit channel subscriptions via API call to the edit channel subscription endpoint.
Cite this page
CVE-2025-54478. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-54478
Use CWE-306, Mattermost vendor hub and Confluence product page to widen CVE-2025-54478 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-13523, CVE-2025-54525 and CVE-2025-52931 for nearby disclosures in the same product family.