Mattermost Authorization Vulnerability in Viewer Role Allowing Unauthorized Access to Statistics

Vulnerability

An authorization vulnerability has been identified in Mattermost versions 9.11.x prior to 9.11.8. The issue arises in the Viewer role, which is not properly authorized, allowing attackers with this role—especially those configured with No Access to Reporting—to still view team and site statistics.

Impact

Exploitation of this vulnerability allows unauthorized access to team and site statistics, bypassing the intended restrictions of the Viewer role.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.