Mattermost Incorrect Authorization vulnerability
Moderate severity
GitHub Reviewed
Published
Jun 30, 2025
to the GitHub Advisory Database
•
Updated Jun 30, 2025
Package
Affected versions
< 0.0.0-20250513065225-4ae5d647fb88
Patched versions
0.0.0-20250513065225-4ae5d647fb88
< 8.0.0-20250513065225-4ae5d647fb88
>= 9.11.0, < 9.11.16
>= 10.5.0, < 10.5.6
>= 10.6.0, < 10.6.6
>= 10.7.0, < 10.7.3
>= 10.8.0, < 10.8.1
8.0.0-20250513065225-4ae5d647fb88
9.11.16
10.5.6
10.6.6
10.7.3
10.8.1
Description
Published by the National Vulnerability Database
Jun 30, 2025
Published to the GitHub Advisory Database
Jun 30, 2025
Reviewed
Jun 30, 2025
Last updated
Jun 30, 2025
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions when adding participants to playbook runs. This allows authenticated users with member-level permissions to bypass system admin restrictions and add or remove users to/from private channels via the playbook run participants feature, even when the 'Manage Members' permission has been explicitly removed. This can lead to unauthorized access to sensitive channel content and allow guest users to gain channel management privileges.
References