CVE-2025-1792

EUVD-2025-16489
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.1 LOW
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
mattermostmattermost_server
9.11.0 ≤
𝑥
< 9.11.13
mattermostmattermost_server
10.5.0 ≤
𝑥
< 10.5.4
mattermostmattermost_server
10.7.0 ≤
𝑥
< 10.7.1
𝑥
= Vulnerable software versions