Low severity3.1NVD Advisory· Published May 30, 2025· Updated Jun 17, 2026
CVE-2025-3611
CVE-2025-3611
Description
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/mattermost/mattermost/server/v8Go | >= 10.6.0-rc1, < 10.7.1 | 10.7.1 |
github.com/mattermost/mattermost/server/v8Go | >= 10.0.0-rc1, < 10.5.4 | 10.5.4 |
github.com/mattermost/mattermost/server/v8Go | >= 9.0.0-rc1, < 9.11.13 | 9.11.13 |
github.com/mattermost/mattermost/server/v8Go | < 8.0.0-20250414154356-6f33b721de76 | 8.0.0-20250414154356-6f33b721de76 |
Affected products
13- osv-coords8 versionspkg:apk/chainguard/mattermost-10.6pkg:golang/github.com/mattermost/mattermost/server/v8pkg:apk/wolfi/mattermost-10.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Tumbleweedpkg:apk/chainguard/mattermost-10.6-compatpkg:apk/chainguard/mattermost-fips-10.6pkg:apk/chainguard/mattermost-fips-10.6-compatpkg:apk/wolfi/mattermost-10.6-compat
< 0+ 7 more
- (no CPE)range: < 0
- (no CPE)range: >= 10.6.0-rc1, < 10.7.1
- (no CPE)range: < 0
- (no CPE)range: < 0.0.20250612T141001-1.1
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
10.7.0+ 4 more
- (no CPE)range: 10.7.0
- cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*range: >=9.11.0,<9.11.13
- cpe:2.3:a:mattermost:mattermost_server:10.7.0:-:*:*:*:*:*:*
- cpe:2.3:a:mattermost:mattermost_server:10.7.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:mattermost:mattermost_server:10.7.0:rc2:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-86jg-35xj-3vv5ghsaADVISORY
- mattermost.com/security-updatesnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-3611ghsaADVISORY
- github.com/mattermost/mattermost/commit/6f33b721de76b39a7714bfe0d5e9c1306869a3e3ghsaWEB
News mentions
0No linked articles in our index yet.