First published: Fri Mar 21 2025(Updated: )
Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channel, which team admins to joining private channels via crafted permalink links without explicit consent from them.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost | <=9.11.8 | |
go/github.com/mattermost/mattermost/server/v8 | >=9.11.0<9.11.9 | 9.11.9 |
Mattermost | >=9.11.0<9.11.9 |
Update Mattermost to versions 10.5.0, 9.11.9 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27715 is considered a medium-severity vulnerability due to its potential for unauthorized access to private channels.
To fix CVE-2025-27715, upgrade Mattermost to version 9.11.9 or later where the vulnerability has been addressed.
The potential risks of CVE-2025-27715 include unauthorized additions of team admins to private channels without consent.
Mattermost versions 9.11.x up to and including 9.11.8 are affected by CVE-2025-27715.
Yes, an attacker can exploit CVE-2025-27715 remotely by using crafted permalink links to gain access to private channels.