Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup configuration option is enabled when a user requests to switch from SAML to Email. This allows the user to switch their authentication mail from SAML to email and possibly edit personal details that were otherwise non-editable and provided by the SAML provider.
Fixes

Solution

Update Mattermost to versions 9.8.0, 9.5.4, 9.7.2, 9.6.2, 8.1.13 or higher.


Workaround

No workaround given by the vendor.

References
History

Tue, 30 Sep 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-01T21:11:12.407Z

Reserved: 2024-05-23T13:51:58.596Z

Link: CVE-2024-5270

cve-icon Vulnrichment

Updated: 2024-08-01T21:11:12.407Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-26T14:15:10.303

Modified: 2025-09-30T15:47:34.487

Link: CVE-2024-5270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:09:40Z