Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://mattermost.com/security-updates |
![]() ![]() |
History
Tue, 08 Jul 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mattermost
Mattermost mattermost Server |
|
CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.7.0:-:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.7.0:rc1:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.7.0:rc2:*:*:*:*:*:* |
|
Vendors & Products |
Mattermost
Mattermost mattermost Server |
Fri, 30 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 30 May 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console. | |
Title | Improper Access Control in Mattermost allows System Managers to view team details despite role restrictions | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Mattermost
Published: 2025-05-30T14:22:09.854Z
Updated: 2025-05-30T14:37:42.109Z
Reserved: 2025-04-14T20:40:50.972Z
Link: CVE-2025-3611

Updated: 2025-05-30T14:37:32.312Z

Status : Analyzed
Published: 2025-05-30T15:15:41.197
Modified: 2025-07-08T17:11:34.797
Link: CVE-2025-3611

No data.