← back
CVE-2025-3611lowCWE-863

Improper Access Control in Mattermost allows System Managers to view team details despite role restrictions

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 3.1epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
Mattermost · Mattermost