CVE-2025-9076

MEDIUM

Mattermost <10.10.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 14.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (3)
mattermost/mattermost 0 - 8.0.0-20250729073403-517ae758cd02Go
mattermost/mattermost-server 10.10.0 - 10.10.2Go
mattermost/mattermost_server 10.10.0 - 10.10.2
Published Sep 15, 2025
Tracked Since Feb 18, 2026