Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the RelayState

Subscriptions

Vendors Products
Mattermost Subscribe
Mattermost Subscribe
Mattermost Server Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-r6qj-894f-5hr2 Mattermost has a Missing Authorization vulnerability
Fixes

Solution

Update Mattermost to versions 10.12.0, 10.11.2, 10.10.3, 10.5.11 or higher.


Workaround

No workaround given by the vendor.

References
History

Tue, 21 Oct 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server

Mon, 20 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Thu, 16 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Oct 2025 08:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the RelayState
Title Arbitrary Mattermost Team can be joined by manipulating the SAML RelayState
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-02-26T16:57:27.125Z

Reserved: 2025-09-16T08:32:57.321Z

Link: CVE-2025-58075

cve-icon Vulnrichment

Updated: 2025-10-16T13:31:26.087Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-16T09:15:35.030

Modified: 2025-10-21T17:49:14.550

Link: CVE-2025-58075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-20T13:25:22Z

Weaknesses