CVE-2025-9076
BaseFortify
Publication date: 2025-09-15
Last updated on: 2025-09-20
Assigner: Mattermost, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mattermost | mattermost_server | From 10.10.0 (inc) to 10.10.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability occurs in Mattermost versions 10.10.x up to 10.10.1, where the software fails to properly sanitize user data during the synchronization of shared channel memberships. As a result, malicious or compromised remote clusters can access sensitive user information through unsanitized user objects. This issue affects Mattermost Server instances that have shared channels enabled.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access to sensitive user information by malicious or compromised remote clusters. This can result in exposure of confidential data, potentially leading to privacy breaches and increased risk of further attacks or misuse of user information.