← Back

CVE-2025-41436

nvd nist
Published: Nov 14, 2025Modified: Nov 17, 2025

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads

Affected (1)

1 product
Mattermost Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 11.0.0

References (1)

Source: responsibledisclosure@mattermost.com
Vendor Advisory

Timeline

No history available yet.