Cross-team channel membership access
Vulnerability Description
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11777
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Xiangyu Guo
References
More from Mattermost
View All →Affected Vendor
Mattermost
View all reports →