CVE-2025-1792: Improper Access Control in Mattermost Channel Member API
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1792?
CVE-2025-1792 is considered a medium-severity vulnerability due to improper access controls affecting guest users.
How do I fix CVE-2025-1792?
To fix CVE-2025-1792, update Mattermost to version 10.7.1 or later, 10.5.4 or later, or 9.11.13 or later.
Who is affected by CVE-2025-1792?
CVE-2025-1792 affects users of Mattermost versions 10.7.x up to and including 10.7.0, 10.5.x up to and including 10.5.3, and 9.11.x up to and including 9.11.12.
What type of information can guest users access due to CVE-2025-1792?
Due to CVE-2025-1792, authenticated guest users can access metadata about members of public channels via the channel members API.
Is there a workaround for CVE-2025-1792 if I cannot update Mattermost immediately?
There is no official workaround for CVE-2025-1792, so updating to a patched version is the recommended solution.