Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects
References
History

Tue, 25 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server

Fri, 21 Nov 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Tue, 18 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Nov 2025 15:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which allows other users to determine when users had read channels via channel member objects
Title Channel member objects leak read status
Weaknesses CWE-1426
References
Metrics cvssV3_1

{'score': 3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published: 2025-11-18T15:23:29.642Z

Updated: 2025-11-18T21:03:22.890Z

Reserved: 2025-10-15T11:42:23.835Z

Link: CVE-2025-55074

cve-icon Vulnrichment

Updated: 2025-11-18T21:03:17.275Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-18T16:15:44.500

Modified: 2025-11-25T20:24:39.843

Link: CVE-2025-55074

cve-icon Redhat

No data.