FlawAtlas
Search the atlas
CVE-2025-1792 Low

Mattermost fails to properly enforce access controls for guest users

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.

Exploit probability 0.2%
Published May 30, 2025
Required by Not available
Last source change August 7, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/mattermost/mattermost-server
Go github.com/mattermost/mattermost-server/v5
Go github.com/mattermost/mattermost-server/v6
Go github.com/mattermost/mattermost/server/v8
Go github.com/mattermost/mattermost/server/v8
Unknown Unknown

50 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-1792

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.

View original source
Open Source Vulnerabilities GO-2025-3730

Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server

View original source
Open Source Vulnerabilities GHSA-hc6v-386m-93pq

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.

View original source

05 / REFERENCES

Further evidence