PT-2026-91745 · Mattermost · Mattermost
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Mattermost version 11.9.0
Mattermost versions 11.8.x through 11.8.4
Mattermost versions 11.7.x through 11.7.7
Mattermost versions 10.11.x through 10.11.22
Description
An issue exists where Team objects returned by the data retention teams endpoint are not properly sanitized. This allows an authenticated user with read-only Data Retention Policy permissions to obtain the secret
invite id and email of a private team, enabling unauthorized access to join that team. The issue is triggered via the 'GET /api/v4/data retention/policies/{policy id}/teams' endpoint.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Restrict access to the 'GET /api/v4/data retention/policies/{policy id}/teams' endpoint to minimize the risk of exploitation.
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mattermost