Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from public and private channels by manipulating playbook run participants when the run is linked to a channel.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://mattermost.com/security-updates |
![]() ![]() |
History
Tue, 08 Jul 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mattermost
Mattermost mattermost Server |
|
CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:-:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:rc1:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:rc2:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:rc3:*:*:*:*:*:* |
|
Vendors & Products |
Mattermost
Mattermost mattermost Server |
Mon, 23 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 20 Jun 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from public and private channels by manipulating playbook run participants when the run is linked to a channel. | |
Title | Unauthorized channel member management through playbook runs | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Mattermost
Published: 2025-06-20T14:31:48.644Z
Updated: 2025-06-23T20:44:50.189Z
Reserved: 2025-04-03T15:26:04.216Z
Link: CVE-2025-3227

Updated: 2025-06-23T20:44:45.867Z

Status : Analyzed
Published: 2025-06-20T15:15:20.430
Modified: 2025-07-08T14:31:06.530
Link: CVE-2025-3227

No data.