CVE-2025-3611 LOW

CVE-2025-3611: Improper Access Control in Mattermost allows System Managers to view team details despite role restrictions

Vendor Mattermost
Product Mattermost
Weakness CWE-863 · Incorrect authorization
Published May 30, 2025
Last update May 30, 2025

CVSS base score

3.1/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.

Key dates

02Disclosure timeline

May 30, 2025 CVE published
May 30, 2025 Record updated