Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-09-15 10:15
Updated : 2025-09-20 02:52
NVD link : CVE-2025-9076
Mitre link : CVE-2025-9076
CVE.ORG link : CVE-2025-9076
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-862
Missing Authorization
