Impact
Mattermost fails to enforce the manage_shared_channels permission when processing the /share-channel autocomplete handler, exposing an authorization weakness per CWE-862. This flaw allows an authenticated user without that permission to request and enumerate metadata about remote cluster connections through slash command autocomplete, resulting in the disclosure of cluster configuration details.
Affected Systems
Affected vendors and products include Mattermost. Specifically, Mattermost server versions 10.11.x up to 10.11.19, 11.6.x up to 11.6.4, and 11.7.x up to 11.7.2 are vulnerable.
Risk and Exploitability
The CVSS base score of 4.3 indicates a moderate risk for information disclosure. Because the vulnerability requires an authenticated user, it is not a remote code execution flaw but permits unauthorized disclosure of cluster metadata via normal slash command autocomplete usage. The EPSS score of <1% signals a low exploitation probability, and the issue is not listed in CISA’s KEV catalog, implying limited public exploitation. The likely attack vector is routine use of the slash command autocomplete feature by an authenticated user lacking the manage_shared_channels permission.
OpenCVE Enrichment