PT-2025-37464 · Mattermost · Mattermost

Daw10

·

Published

2025-09-15

·

Updated

2025-09-22

·

CVE-2025-9076

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 10.10.x through 10.10.1
Description Mattermost Server instances with shared channels enabled are susceptible to an information disclosure issue. The software fails to properly sanitize user data during shared channel membership synchronization, potentially allowing malicious or compromised remote clusters to access sensitive user information via unsanitized user objects.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-9076
GHSA-3VCM-C42P-3HHF
GO-2025-3950
OPENSUSE-SU-2025:15564-1
SUSE-SU-2025:03289-1

Affected Products

Mattermost