Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29165 | Mattermost Missing Authorization vulnerability |
Github GHSA |
GHSA-3vcm-c42p-3hhf | Mattermost Missing Authorization vulnerability |
Solution
Update Mattermost to versions 10.11.0, 10.10.2 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Mon, 22 Sep 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Server
|
Wed, 17 Sep 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Mon, 15 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Sep 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled. | |
| Title | Mattermost Server exposes sensitive user credentials during shared channel membership synchronization | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-09-15T14:05:16.235Z
Reserved: 2025-08-15T15:26:17.148Z
Link: CVE-2025-9076
Updated: 2025-09-15T14:05:11.941Z
Status : Analyzed
Published: 2025-09-15T10:15:32.450
Modified: 2025-09-20T02:52:38.957
Link: CVE-2025-9076
No data.
OpenCVE Enrichment
Updated: 2025-09-17T10:08:38Z
EUVD
Github GHSA