CVE-2025-3446: Members Without Guest Invite Permissions Can Add Guests to Teams
Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4.x <= 10.4.4, 9.11.x <= 9.11.11 fail to check the correct permissions which allows authenticated users who only have permission to invite non-guest users to a team to add guest users to that team via the API to add a single user to a team.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3446?
CVE-2025-3446 is classified as a medium severity vulnerability due to its potential to allow unauthorized access to guest user permissions.
How do I fix CVE-2025-3446?
To fix CVE-2025-3446, upgrade Mattermost to versions 10.6.2 or higher, 10.5.3 or higher, 10.4.5 or higher, or 9.11.12 or higher.
What versions of Mattermost are affected by CVE-2025-3446?
CVE-2025-3446 affects Mattermost versions 10.6.x through 10.6.1, 10.5.x through 10.5.2, 10.4.x through 10.4.4, and 9.11.x through 9.11.11.
What type of permissions are improperly managed in CVE-2025-3446?
CVE-2025-3446 improperly manages permissions related to inviting guest users within the API by authenticated users.
Who is at risk from CVE-2025-3446?
Authenticated users with limited permissions to invite non-guest users could exploit CVE-2025-3446 to add guest users without adequate authorization.