Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint
References
History

Mon, 17 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server

Fri, 14 Nov 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Thu, 13 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Nov 2025 17:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint
Title Cross-team channel membership access
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2025-11-13T17:32:03.975Z

Updated: 2025-11-13T18:01:46.459Z

Reserved: 2025-10-15T11:37:25.782Z

Link: CVE-2025-11777

cve-icon Vulnrichment

Updated: 2025-11-13T18:01:42.725Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-13T18:15:49.393

Modified: 2025-11-17T18:05:07.173

Link: CVE-2025-11777

cve-icon Redhat

No data.