Improper Channel Management in Mattermost by Mattermost
CVE-2025-46702

5.4MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
30 June 2025

What is CVE-2025-46702?

Several versions of Mattermost exhibit improper enforcement of channel member management permissions. Specifically, when adding participants to playbook runs, authenticated users with member-level permissions can circumvent system admin restrictions. This flaw allows them to add or remove users from private channels despite the 'Manage Members' permission being revoked. As a result, unauthorized access to sensitive content within channels becomes possible, enabling even guest users to acquire channel management capabilities.

Affected Version(s)

Mattermost 10.5.0 <= 10.5.5

Mattermost 9.11.0 <= 9.11.15

Mattermost 10.8.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mrhashimamin
.
CVE-2025-46702 : Improper Channel Management in Mattermost by Mattermost