Impact
Mattermost versions before 11.9.1, 11.8.5, 11.7.8 and 10.11.23 fail to sanitize team objects returned from the data‑retention policies endpoint. An authenticated user who only holds the read‑only Data Retention Policy permission can read the secret invite_id and email address of a private team. With that information the user can construct a join request and become a member of the private team without authorization, thereby gaining access to restricted channels and conversations.
Affected Systems
Mattermost installations using version 10.11.0 through 10.11.22, 11.7.0 through 11.7.7, 11.8.0 through 11.8.4, and 11.9.0 or earlier are affected. All deployments that expose the /api/v4/data_retention/policies/{policy_id}/teams endpoint and grant users read‑only Data Retention Policy rights are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability that the specific conditions required for exploitation—namely an authenticated user with the correct minimal permission—are met. The vulnerability is not listed in CISA’s KEV catalog. If an attacker can meet the prerequisite permissions, they can retrieve the private team’s invite_id and use it to join the team, effectively bypassing team membership controls.
OpenCVE Enrichment