CVE-2025-9076

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-09-15 10:15

Updated : 2025-09-20 02:52


NVD link : CVE-2025-9076

Mitre link : CVE-2025-9076

CVE.ORG link : CVE-2025-9076


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-862

Missing Authorization