CVE-2025-27933
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Mar 21, 2025
Updated: Mar 27, 2025
CWE ID 863
Summary
CVE-2025-27933 is a vulnerability affecting Mattermost versions 10.4.x up to 10.4.2, 10.3.x up to 10.3.3, and 9.11.x up to 9.11.8. This issue arises from the failure to enforce channel conversion restrictions. Consequently, members with the necessary permissions to convert public channels into private ones can also convert private channels into public ones, posing a significant risk to data privacy. This vulnerability underscores the importance of maintaining up-to-date software to ensure security.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mattermost Server
Affected Vendors
- Mattermost, Inc.