Team Membership Permissions Vulnerability in Mattermost
CVE-2025-11777

3.1LOW

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
13 November 2025

What is CVE-2025-11777?

The affected Mattermost versions fail to properly validate team membership permissions in the Add Channel Member API. This security oversight allows users from one team to gain unauthorized access to sensitive user metadata and channel membership information belonging to other teams. By exploiting this vulnerability, an attacker could retrieve private data via the API endpoint, raising serious concerns about data confidentiality and integrity within the Mattermost platform.

Affected Version(s)

Mattermost 10.11.0 <= 10.11.3

Mattermost 10.5.0 <= 10.5.11

Mattermost 11.0.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xiangyu Guo
.
CVE-2025-11777 : Team Membership Permissions Vulnerability in Mattermost