FlawAtlas
Search the atlas
CVE-2025-3611 Low

Mattermost fails to properly enforce access control restrictions for System Manager roles

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.

Exploit probability 0.2%
Published May 30, 2025
Required by Not available
Last source change August 7, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/mattermost/mattermost/server/v8
Go github.com/mattermost/mattermost-server
Go github.com/mattermost/mattermost-server/v5
Go github.com/mattermost/mattermost-server/v6
Go github.com/mattermost/mattermost/server/v8
Unknown Unknown

47 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2025-3728

Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server

View original source
Open Source Vulnerabilities CVE-2025-3611

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.

View original source
Open Source Vulnerabilities GHSA-86jg-35xj-3vv5

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests to team endpoints, even when explicitly configured with 'No access' to Teams in the System Console.

View original source

05 / REFERENCES

Further evidence