Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-v8fr-vxmw-6mf6: Mattermost Incorrect Authorization vulnerability

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions when adding participants to playbook runs. This allows authenticated users with member-level permissions to bypass system admin restrictions and add or remove users to/from private channels via the playbook run participants feature, even when the ‘Manage Members’ permission has been explicitly removed. This can lead to unauthorized access to sensitive channel content and allow guest users to gain channel management privileges.

ghsa
#vulnerability#git#perl#auth
  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-46702

Mattermost Incorrect Authorization vulnerability

Moderate severity GitHub Reviewed Published Jun 30, 2025 to the GitHub Advisory Database • Updated Jun 30, 2025

Package

gomod github.com/mattermost/mattermost-server (Go)

Affected versions

< 0.0.0-20250513065225-4ae5d647fb88

Patched versions

0.0.0-20250513065225-4ae5d647fb88

gomod github.com/mattermost/mattermost/server/v8 (Go)

< 8.0.0-20250513065225-4ae5d647fb88

>= 9.11.0, < 9.11.16

>= 10.5.0, < 10.5.6

>= 10.6.0, < 10.6.6

>= 10.7.0, < 10.7.3

>= 10.8.0, < 10.8.1

8.0.0-20250513065225-4ae5d647fb88

9.11.16

10.5.6

10.6.6

10.7.3

10.8.1

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions when adding participants to playbook runs. This allows authenticated users with member-level permissions to bypass system admin restrictions and add or remove users to/from private channels via the playbook run participants feature, even when the ‘Manage Members’ permission has been explicitly removed. This can lead to unauthorized access to sensitive channel content and allow guest users to gain channel management privileges.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-46702
  • https://mattermost.com/security-updates
  • mattermost/mattermost@31142f1
  • mattermost/mattermost@4ae5d64

Published to the GitHub Advisory Database

Jun 30, 2025

Last updated

Jun 30, 2025

ghsa: Latest News

GHSA-3m86-c9x3-vwm9: Graylog vulnerable to privilege escalation through API tokens