Access Control Vulnerability in Mattermost Affecting Guest User Permissions
CVE-2025-11776
4.3MEDIUM
What is CVE-2025-11776?
Mattermost versions prior to 11 expose a vulnerability where the archived channel search API does not adequately restrict access for guest users. This flaw allows unauthorized individuals to discover archived public channels through the endpoint /api/v4/teams/{team_id}/channels/search_archived, posing a risk to data confidentiality and privacy within the platform.
Affected Version(s)
Mattermost <11 <= 11
Mattermost 11.0.0