Team Membership Permissions Vulnerability in Mattermost
CVE-2025-11777
3.1LOW
What is CVE-2025-11777?
The affected Mattermost versions fail to properly validate team membership permissions in the Add Channel Member API. This security oversight allows users from one team to gain unauthorized access to sensitive user metadata and channel membership information belonging to other teams. By exploiting this vulnerability, an attacker could retrieve private data via the API endpoint, raising serious concerns about data confidentiality and integrity within the Mattermost platform.
Affected Version(s)
Mattermost 10.11.0 <= 10.11.3
Mattermost 10.5.0 <= 10.5.11
Mattermost 11.0.0