A vulnerability was found in Mattermost up to 9.11.12/10.5.3/10.6.2/10.7.0. It has been classified as critical. Affected is an unknown function of the component Access Token Handler. The manipulation leads to incorrect implementation of authentication algorithm.

This vulnerability is traded as CVE-2025-3230. It is possible to launch the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.