Home
LOW: 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:NDefault status
unaffected
10.11.0 (semver)
affected
11.3.0
unaffected
10.11.10
unaffected
Description
Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisory ID: MMSA-2025-00561
Problem types
CWE-862: Missing Authorization
Product status
10.11.0 (semver)
11.3.0
10.11.10
Credits
omarAhmed1
References
mattermost.com/security-updates (MMSA-2025-00561)