CVE-2025-3611: Improper Access Control in Mattermost allows System Managers to view team details despite role restrictions
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3611?
CVE-2025-3611 is classified as a medium severity vulnerability.
How do I fix CVE-2025-3611?
To mitigate CVE-2025-3611, upgrade to Mattermost version 10.7.1, 10.5.4, or 9.11.13 or later.
What versions of Mattermost are affected by CVE-2025-3611?
CVE-2025-3611 affects Mattermost versions 10.7.0 and earlier, 10.5.3 and earlier, and 9.11.12 and earlier.
What type of access control issue is present in CVE-2025-3611?
CVE-2025-3611 allows authenticated users with System Manager privileges to improperly view restricted team details.
Is CVE-2025-3611 exploitable without authentication?
No, CVE-2025-3611 requires authenticated access to exploit the access control vulnerability.