Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
11.3.0 (semver)
affected
11.2.0 (semver)
affected
10.11.0 (semver)
affected
11.4.0
unaffected
11.3.1
unaffected
11.2.3
unaffected
10.11.11
unaffected
Description
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs during team creation.. Mattermost Advisory ID: MMSA-2025-00565
Problem types
CWE-862: Missing Authorization
Product status
11.3.0 (semver)
11.2.0 (semver)
10.11.0 (semver)
11.4.0
11.3.1
11.2.3
10.11.11
Credits
omarAhmed1
References
mattermost.com/security-updates (MMSA-2025-00565)