CVE-2025-2564: Unauthorized View Access to Archived Channel Member Info
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, which allows authenticated users to view members and member information of archived channels even when this setting is disabled.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2564?
CVE-2025-2564 is classified as a moderate severity vulnerability.
How does CVE-2025-2564 affect Mattermost users?
CVE-2025-2564 allows authenticated users to access member information of archived channels contrary to configured settings.
How do I fix CVE-2025-2564?
To fix CVE-2025-2564, upgrade Mattermost to at least version 10.5.2, 10.4.4, or 9.11.10.
Which versions of Mattermost are vulnerable to CVE-2025-2564?
Mattermost versions 10.5.x up to 10.5.1, 10.4.x up to 10.4.3, and 9.11.x up to 9.11.9 are vulnerable to CVE-2025-2564.
Can unprivileged users exploit CVE-2025-2564?
Yes, unprivileged authenticated users can exploit CVE-2025-2564 to view sensitive information in archived channels.