CVE-2025-41436

LOW

Mattermost < 11.0 - Unauthenticated Archived Channel Access via Open in Channel Functionality

Title source: llm
STIX 2.1

Description

Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads

References (1)

Core 1
Core References

Scores

CVSS v3 3.1
EPSS 0.0003
EPSS Percentile 8.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (3)
mattermost/mattermost 0 - 8.0.0-20250815165020-c8d66301415dGo
mattermost/mattermost-server 0 - 11.0.0-alpha.1Go
mattermost/mattermost_server < 11.0.0
Published Nov 14, 2025
Tracked Since Feb 18, 2026