Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint
Advisories

No advisories yet.

Fixes

Solution

Update Mattermost to versions 11.0.0, 10.11.4, 10.5.12 or higher.


Workaround

No workaround given by the vendor.

References
History

Thu, 13 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Nov 2025 17:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint
Title Cross-team channel membership access
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-11-13T18:01:46.459Z

Reserved: 2025-10-15T11:37:25.782Z

Link: CVE-2025-11777

cve-icon Vulnrichment

Updated: 2025-11-13T18:01:42.725Z

cve-icon NVD

Status : Received

Published: 2025-11-13T18:15:49.393

Modified: 2025-11-13T18:15:49.393

Link: CVE-2025-11777

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.