Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.
References
Link | Resource |
---|---|
https://mattermost.com/security-updates | Vendor Advisory |
Configurations
History
20 Sep 2025, 02:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://mattermost.com/security-updates - Vendor Advisory | |
First Time |
Mattermost mattermost Server
Mattermost |
|
CPE | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* |
15 Sep 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-15 10:15
Updated : 2025-09-20 02:52
NVD link : CVE-2025-9076
Mitre link : CVE-2025-9076
CVE.ORG link : CVE-2025-9076
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-862
Missing Authorization