cbcvebase.
CVE-2025-11776
published 2025-11-14

CVE-2025-11776: Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the…

medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint

Affected

7 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost>= 0 < 5.3.2-0.20250815165020-c8d66301415d5.3.2-0.20250815165020-c8d66301415d
github.commattermost_mattermost-server>= 0 < 5.3.2-0.20250815165020-c8d66301415d5.3.2-0.20250815165020-c8d66301415d
github.commattermost_mattermost-server_v5>= 0 < 5.3.2-0.20250815165020-c8d66301415d5.3.2-0.20250815165020-c8d66301415d
github.commattermost_mattermost-server_v6>= 0 < 5.3.2-0.20250815165020-c8d66301415d5.3.2-0.20250815165020-c8d66301415d
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20250815165020-c8d66301415d8.0.0-20250815165020-c8d66301415d
mattermostmattermost<= <11
mattermostmattermost_server< 11.0.011.0.0