Impact
This vulnerability occurs when Mattermost incorrectly exposes sensitive team details through the data retention teams endpoint. An authenticated user who only has the read‑only Data Retention Policy permission can retrieve the team's secret invite_id and email address. With that information, the user can join a private team without authorization, effectively gaining access to restricted channels and content.
Affected Systems
Affected versions are Mattermost 11.9.x through 11.9.0, 11.8.x through 11.8.4, 11.7.x through 11.7.7, and 10.11.x through 10.11.22. The issue applies to all installations that expose the /api/v4/data_retention/policies/{policy_id}/teams endpoint and grant read‑only Data Retention Policy rights to users.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity. The EPSS score is unavailable, so the current exploitation probability is unknown. Because the vulnerability requires authentication and specific permissions, the attack surface is limited to users who have been granted read‑only Data Retention Policy rights. The vulnerability is not listed in the CISA KEV catalog, but it still permits unauthorized access to private teams.
OpenCVE Enrichment