Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-3227


Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from public and private channels by manipulating playbook run participants when the run is linked to a channel.


Published

2025-06-20T15:15:20.430

Last Modified

2025-07-08T14:31:06.530

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost_server < 9.11.16 Yes
Application mattermost mattermost_server < 10.5.6 Yes
Application mattermost mattermost_server < 10.6.6 Yes
Application mattermost mattermost_server < 10.7.3 Yes
Application mattermost mattermost_server 10.8.0 Yes
Application mattermost mattermost_server 10.8.0 Yes
Application mattermost mattermost_server 10.8.0 Yes
Application mattermost mattermost_server 10.8.0 Yes

References