Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-11-14 08:15
Updated : 2025-11-17 17:52
NVD link : CVE-2025-41436
Mitre link : CVE-2025-41436
CVE.ORG link : CVE-2025-41436
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-863
Incorrect Authorization
