CVE-2025-27715: Auto-Enrollment of Team Admins into Private Channels without explicit consent
Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channel, which team admins to joining private channels via crafted permalink links without explicit consent from them.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 9.11.9 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.5.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 9.11.9
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27715?
CVE-2025-27715 is considered a medium-severity vulnerability due to its potential for unauthorized access to private channels.
How do I fix CVE-2025-27715?
To fix CVE-2025-27715, upgrade Mattermost to version 9.11.9 or later where the vulnerability has been addressed.
What are the potential risks of CVE-2025-27715?
The potential risks of CVE-2025-27715 include unauthorized additions of team admins to private channels without consent.
Which versions of Mattermost are affected by CVE-2025-27715?
Mattermost versions 9.11.x up to and including 9.11.8 are affected by CVE-2025-27715.
Can an attacker exploit CVE-2025-27715 remotely?
Yes, an attacker can exploit CVE-2025-27715 remotely by using crafted permalink links to gain access to private channels.