CVE-2025-22449
CVSS 3.1 Score 3.8 of 10 (low)
Details
Summary
CVE-2025-22449 is a vulnerability affecting Mattermost versions 9.11.x up to 9.11.5. This issue permits team admins, who lack the necessary permission to invite users, to bypass these restrictions by altering the "allow_open_invite" field and making their team publicly accessible. Consequently, unauthorized users can be invited to join affected teams. This security weakness could potentially lead to unintended access and data breaches. It is strongly recommended that users of impacted Mattermost versions upgrade to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mattermost Server
Affected Vendors
- Mattermost, Inc.