Mattermost Team Scheme Role Modification Authorization Vulnerability

Vulnerability

A vulnerability exists in Mattermost versions 10.5.x prior to 10.5.9 and 9.11.x prior to 9.11.17, where the application fails to properly validate authorization for modifications to team scheme roles. This flaw allows Team Admins to unjustly demote Team Members to Guests by using the PUT /api/v4/teams/team-id/members/user-id/schemeRoles API endpoint.

Impact

Exploitation of this vulnerability allows unauthorized role demotions, where Team Admins can downgrade Team Members to Guests, potentially leading to a loss of privileges and access rights within the team.

Remediation

Users can upgrade to Mattermost versions 10.11.010.5.10 or 10.11.010.5.99.11.18 to address this vulnerability.

Added: Aug 21, 2025, 8:18 AM
Updated: Aug 21, 2025, 8:18 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.