Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.
Fixes

Solution

Update Mattermost to versions 10.11.0, 10.10.2 or higher.


Workaround

No workaround given by the vendor.

References
History

Mon, 15 Sep 2025 10:15:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.
Title Mattermost Server exposes sensitive user credentials during shared channel membership synchronization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-09-15T10:06:15.094Z

Reserved: 2025-08-15T15:26:17.148Z

Link: CVE-2025-9076

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-09-15T10:15:32.450

Modified: 2025-09-15T10:15:32.450

Link: CVE-2025-9076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.