CVE-2025-27715

CVSS 3.1 Score 2.7 of 10 (low)

Details

Published Mar 21, 2025
Updated: Mar 27, 2025
CWE ID 863

Summary

CVE-2025-27715 is a vulnerability affecting Mattermost versions 9.11.x up to 9.11.8. This issue allows team admins to be added to private channels without their explicit consent, due to a lack of approval prompt. An attacker can exploit this vulnerability by crafting permalink links to join private channels, potentially compromising the privacy and security of the affected channels. Organizations using Mattermost are advised to update to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mattermost Server

Affected Vendors

  • Mattermost, Inc.