CVE-2025-27715
CVSS 3.1 Score 2.7 of 10 (low)
Details
Published Mar 21, 2025
Updated: Mar 27, 2025
CWE ID 863
Summary
CVE-2025-27715 is a vulnerability affecting Mattermost versions 9.11.x up to 9.11.8. This issue allows team admins to be added to private channels without their explicit consent, due to a lack of approval prompt. An attacker can exploit this vulnerability by crafting permalink links to join private channels, potentially compromising the privacy and security of the affected channels. Organizations using Mattermost are advised to update to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mattermost Server
Affected Vendors
- Mattermost, Inc.