Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.
Metrics
Affected Vendors & Products
Fixes
Solution
Update Mattermost to versions 10.11.0, 10.10.2 or higher.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://mattermost.com/security-updates |
![]() ![]() |
History
Mon, 15 Sep 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled. | |
Title | Mattermost Server exposes sensitive user credentials during shared channel membership synchronization | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-09-15T10:06:15.094Z
Reserved: 2025-08-15T15:26:17.148Z
Link: CVE-2025-9076

No data.

Status : Received
Published: 2025-09-15T10:15:32.450
Modified: 2025-09-15T10:15:32.450
Link: CVE-2025-9076

No data.

No data.