CVE-2025-14350
published 2026-02-16CVE-2025-14350: Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.16%
5.8th percentile
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated users to determine the existence of teams and their URL names via posting channel shortlinks and observing the channel_mentions property in the API response. Mattermost Advisory ID: MMSA-2025-00563
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 5.3.2-0.20251209134645-761e56bb11cc | 5.3.2-0.20251209134645-761e56bb11cc |
| github.com | mattermost_mattermost-server | >= 10.11.0 | — |
| github.com | mattermost_mattermost-server | >= 10.11.0+incompatible | — |
| github.com | mattermost_mattermost-server | >= 11.1.0 | — |
| github.com | mattermost_mattermost-server | >= 11.1.0+incompatible | — |
| github.com | mattermost_mattermost-server | >= 11.2.0 | — |
| github.com | mattermost_mattermost-server | >= 11.2.0+incompatible | — |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20251209134645-761e56bb11cc | 8.0.0-20251209134645-761e56bb11cc |
| mattermost | mattermost | 10.11.0 – 10.11.9 | — |
| mattermost | mattermost | 11.1.0 – 11.1.2 | — |
| mattermost | mattermost | 11.2.0 – 11.2.1 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.10 | 10.11.10 |
| mattermost | mattermost_server | >= 11.1.0 < 11.1.3 | 11.1.3 |
| mattermost | mattermost_server | >= 11.2.0 < 11.2.2 | 11.2.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server
osv·2026-02-23
CVE-2025-14350 Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server
Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc.
OSV
Mattermost fails to properly validate team membership when processing channel mentions
osv·2026-02-16
CVE-2025-14350 [MEDIUM] Mattermost fails to properly validate team membership when processing channel mentions
Mattermost fails to properly validate team membership when processing channel mentions
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated users to determine the existence of teams and their URL names via posting channel shortlinks and observing the channel_mentions property in the API response. Mattermost Advisory ID: MMSA-2025-00563
GHSA
Mattermost fails to properly validate team membership when processing channel mentions
ghsa·2026-02-16
CVE-2025-14350 [MEDIUM] CWE-862 Mattermost fails to properly validate team membership when processing channel mentions
Mattermost fails to properly validate team membership when processing channel mentions
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated users to determine the existence of teams and their URL names via posting channel shortlinks and observing the channel_mentions property in the API response. Mattermost Advisory ID: MMSA-2025-00563
No detection rules found.
No public exploits indexed.
2026-02-16
Published