Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-18758 | Mattermost allows unauthorized channel member management through playbook runs |
![]() |
GHSA-qwwm-c582-82rx | Mattermost allows unauthorized channel member management through playbook runs |
Solution
Update Mattermost to versions 10.9.0, 10.5.6, 9.11.16, 10.8.1, 10.7.3, 10.6.6 or higher.
Workaround
No workaround given by the vendor.
Link | Providers |
---|---|
https://mattermost.com/security-updates |
![]() ![]() |
Tue, 08 Jul 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mattermost
Mattermost mattermost Server |
|
CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:-:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:rc1:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:rc2:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.8.0:rc3:*:*:*:*:*:* |
|
Vendors & Products |
Mattermost
Mattermost mattermost Server |
Mon, 23 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 20 Jun 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from public and private channels by manipulating playbook run participants when the run is linked to a channel. | |
Title | Unauthorized channel member management through playbook runs | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-06-23T20:44:50.189Z
Reserved: 2025-04-03T15:26:04.216Z
Link: CVE-2025-3227

Updated: 2025-06-23T20:44:45.867Z

Status : Analyzed
Published: 2025-06-20T15:15:20.430
Modified: 2025-07-08T14:31:06.530
Link: CVE-2025-3227

No data.

Updated: 2025-06-23T08:20:14Z