Impact
The vulnerability allows any authenticated ordinary group or direct message member to set the group_constrained flag on a channel through the channel patch API. Because the flag is not appropriately restricted to only public or private channels that support group synchronization, the member can remove all participants from the conversation, effectively ending the channel. This loss of channel membership disrupts communication within the affected channel.
Affected Systems
Mattermost versions 10.11.x up to 10.11.19, 11.6.x up to 11.6.4, and 11.7.x up to 11.7.2 are impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk level. The EPSS score of <1% suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. An attacker only needs basic authenticated access to a channel as a regular member and can use the channel patch API to trigger the flaw. No elevated privileges are required, making the vulnerability a realistic threat in environments where ordinary members have unrestricted patch rights.
OpenCVE Enrichment