Impact
Certain older versions of Mattermost fail to sanitize data returned by the scheme teams endpoint. A user with the User Manager role can retrieve private invitation links for teams they are not a member of and then use those links to join or share access to those private teams via the same endpoint. This flaw effectively allows the attacker to gain unauthorized access to confidential team data.
Affected Systems
The vulnerability affects Mattermost deployments running any of the following releases: 11.7.0 through 11.7.2 and 10.11.0 through 10.11.19. These impacted versions only pose a risk if a User Manager role is assigned to logged‑in users, because that role is required to query the vulnerable endpoint.
Risk and Exploitability
The CVSS score of 3.8 identifies the flaw as low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog. Based on the description, it is inferred that the primary attack vector is an insider or a credential‑stealing attacker who can authenticate with a User Manager account; no external unauthenticated exploitation path is described.
OpenCVE Enrichment