Vulnerability Description
Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mattermost | Mattermost Server | < 11.0.0 |
Related Weaknesses (CWE)
References
- https://mattermost.com/security-updatesVendor Advisory
FAQ
What is CVE-2025-41436?
CVE-2025-41436 is a vulnerability with a CVSS score of 3.1 (LOW). Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel"...
How severe is CVE-2025-41436?
CVE-2025-41436 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-41436?
Check the references section above for vendor advisories and patch information. Affected products include: Mattermost Mattermost Server.