Mattermost Guest User Permission Vulnerability in Private Channels

Vulnerability

A vulnerability exists in Mattermost versions 10.5.x through 10.5.10 and 10.11.x through 10.11.2, where guest user permissions are not properly validated when adding members to private channels. This flaw allows guest users to add any team members to their private channels via the channels/{channel_id}/members API endpoint.

Impact

Exploitation of this vulnerability could lead to unauthorized addition of team members to private channels by guest users.

Remediation

Users can upgrade to Mattermost version 11.0.0 or 10.12.0 to address this vulnerability.

Added: Oct 16, 2025, 9:22 AM
Updated: Oct 16, 2025, 3:57 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.