CVE-2025-1472

MEDIUM

Mattermost 9.11.0-9.11.8 - Incorrect Authorization for Viewer Role

Title source: llm
STIX 2.1

Description

Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0024
EPSS Percentile 47.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (3)
mattermost/mattermost 9.11.0 - 9.11.9Go
mattermost/mattermost-server 9.11.0 - 9.11.9Go
mattermost/mattermost_server 9.11.0 - 9.11.9
Published Mar 19, 2025
Tracked Since Feb 18, 2026