CVE-2025-9076

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

20 Sep 2025, 02:52

Type Values Removed Values Added
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
First Time Mattermost mattermost Server
Mattermost
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

15 Sep 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-15 10:15

Updated : 2025-09-20 02:52


NVD link : CVE-2025-9076

Mitre link : CVE-2025-9076

CVE.ORG link : CVE-2025-9076


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-862

Missing Authorization