Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Joram Wilander

#53032of 53,633
3.3Total CVSS
Vulnerabilities · 1
PT-2025-12407
3.3
2025-03-21
Mattermost · Mattermost · CVE-2025-27715
**Name of the Vulnerable Software and Affected Versions** Mattermost versions 9.11.x through 9.11.8 **Description** The issue concerns the lack of explicit approval before adding a team admin to a private channel. This allows team admins to join private channels via crafted permalink links without explicit consent. **Recommendations** For Mattermost versions 9.11.x through 9.11.8, consider restricting access to private channels until a fix is available, and ensure that team admins are aware of the potential for unauthorized access to these channels.