Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Update Mattermost to versions 11.0.0 or higher.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Fri, 14 Nov 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads | |
| Title | Unauthorized access to archived channel content via threads interface | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-11-14T08:00:42.467Z
Reserved: 2025-10-15T11:16:32.223Z
Link: CVE-2025-41436
No data.
Status : Received
Published: 2025-11-14T08:15:45.310
Modified: 2025-11-14T08:15:45.310
Link: CVE-2025-41436
No data.
OpenCVE Enrichment
No data.