CVE-2025-27933: Unauthorized Private-to-Public Channel Conversion
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to fail to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public
Other sources
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to to enforce channel conversion restrictions, which allows members with permission to convert public channels to private ones to also convert private ones to public.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 8.0.0-20250218135018-e644e3c8e393 - Upgrade
Upgrade
go/github.com/mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 9.11.9 - Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 9.11.9 - Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 10.3.4 - Upgrade
Upgrade
go/github.com/mattermost/mattermost/server/v8to a version that resolves this vulnerability.Fixed in 10.4.3 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.5.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.4.3 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.3.4 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 9.11.9
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27933?
CVE-2025-27933 has a medium severity level as it allows improper channel conversion leading to potential data exposure.
How do I fix CVE-2025-27933?
To resolve CVE-2025-27933, upgrade Mattermost to version 10.4.3 or higher, 10.3.4 or higher, or 9.11.9 or higher.
What versions are affected by CVE-2025-27933?
CVE-2025-27933 affects Mattermost versions 10.4.x up to 10.4.2, 10.3.x up to 10.3.3, and 9.11.x up to 9.11.8.
What is the exploit path for CVE-2025-27933?
CVE-2025-27933 can be exploited by users with permissions to convert public channels to private channels, allowing inappropriate conversions.
Is CVE-2025-27933 under active exploitation?
There is currently no public information suggesting that CVE-2025-27933 is under active exploitation.