← Zuruck zu CVEs
CVE-2025-14573
LOW3.8
Beschreibung
Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisory ID: MMSA-2025-00561
CVE Details
CVSS v3.1 Bewertung3.8
SchweregradLOW
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienHIGH
BenutzerinteraktionNONE
Veroffentlicht2/16/2026
Zuletzt geandert2/18/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
mattermost:mattermost_server
Schwachen (CWE)
CWE-862
Referenzen
https://mattermost.com/security-updates(responsibledisclosure@mattermost.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.