CVE-2025-3611Low· 3.1▾ SunlitMattermost fails to properly enforce access control restrictions for System Manager roles
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.2%
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.
github.com/mattermost/mattermost/server/v8 >= 10.6.0-rc1, < 10.7.1github.com/mattermost/mattermost/server/v8 >= 10.0.0-rc1, < 10.5.4github.com/mattermost/mattermost/server/v8 >= 9.0.0-rc1, < 9.11.13github.com/mattermost/mattermost/server/v8 < 8.0.0-20250414154356-6f33b721de76Upgrade to a patched release:
github.com/mattermost/mattermost/server/v8 10.7.1github.com/mattermost/mattermost/server/v8 10.5.4github.com/mattermost/mattermost/server/v8 9.11.13github.com/mattermost/mattermost/server/v8 8.0.0-20250414154356-6f33b721de76Connected by shared product, vendor, weakness, or advisory.
CVE-2023-6202Medium· 4.3Mattermost Improper Access Control vulnerability
CVE-2025-22445Low· 3.5Mattermost has Improper Check for Unusual or Exceptional Conditions
CVE-2024-46872Medium· 4.6Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
CVE-2024-47401Medium· 4.3Mattermost Server vulnerable to application crash from attacker-generated large response
CVE-2024-10241Medium· 4.3Mattermost Server allows user to get private channel names
CVE-2025-2475Medium· 5.4Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm