Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-46702


Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions when adding participants to playbook runs. This allows authenticated users with member-level permissions to bypass system admin restrictions and add or remove users to/from private channels via the playbook run participants feature, even when the 'Manage Members' permission has been explicitly removed. This can lead to unauthorized access to sensitive channel content and allow guest users to gain channel management privileges.


Published

2025-06-30T17:15:32.600

Last Modified

2025-07-08T14:11:52.077

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost_server < 9.11.16 Yes
Application mattermost mattermost_server < 10.5.6 Yes
Application mattermost mattermost_server < 10.6.6 Yes
Application mattermost mattermost_server < 10.7.3 Yes
Application mattermost mattermost_server 10.8.0 Yes
Application mattermost mattermost_server 10.8.0 Yes
Application mattermost mattermost_server 10.8.0 Yes
Application mattermost mattermost_server 10.8.0 Yes

References