Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups/<group-id>/channels/<channel-id>/link endpoint which allows a user to learn the members of an AD/LDAP group that is linked to a team by adding the group to a channel, even if the user has no access to the team.
Fixes

Solution

Update Mattermost to versions 9.8.0, 9.5.4, 9.7.2, 8.1.13 or higher.


Workaround

No workaround given by the vendor.

References
History

Tue, 30 Sep 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2024-08-02T02:42:59.966Z

Reserved: 2024-05-23T10:57:59.882Z

Link: CVE-2024-34029

cve-icon Vulnrichment

Updated: 2024-08-02T02:42:59.966Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-26T14:15:09.367

Modified: 2025-09-30T15:26:42.900

Link: CVE-2024-34029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T21:08:02Z