CVE-2025-32093Medium· 4.7▾ SunlitMattermost Fails to Restrict Certain Operations on System Admins
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to restrict certain operations on system admins to only other system admins, which allows delegated granular administration users with the "Edit Other Users" permission to perform unauthorized modifications to system administrators via improper permission validation.
github.com/mattermost/mattermost-server >= 10.5.0, < 10.5.2github.com/mattermost/mattermost-server >= 10.4.0, < 10.4.4github.com/mattermost/mattermost-server >= 9.11.0, < 9.11.10github.com/mattermost/mattermost/server/v8 >= 10.5.0, < 10.5.2github.com/mattermost/mattermost/server/v8 >= 10.4.0, < 10.4.4github.com/mattermost/mattermost/server/v8 >= 9.11.0, < 9.11.10github.com/mattermost/mattermost/server/v8 < 8.0.0-20250227102013-aa4623a93199Upgrade to a patched release:
github.com/mattermost/mattermost-server 10.5.2github.com/mattermost/mattermost-server 10.4.4github.com/mattermost/mattermost-server 9.11.10github.com/mattermost/mattermost/server/v8 10.5.2github.com/mattermost/mattermost/server/v8 10.4.4github.com/mattermost/mattermost/server/v8 9.11.10github.com/mattermost/mattermost/server/v8 8.0.0-20250227102013-aa4623a93199Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6062Medium· 6.4Mattermost doesn't validate channel ownership of an existing subscription before applying edits
CVE-2026-6673Medium· 6.4Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue share…
CVE-2026-5139Medium· 5.4Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler
CVE-2026-8074Low· 3.8Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
CVE-2026-9162Medium· 4.3Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation
CVE-2026-3433Medium· 4.3Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel