6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Description
Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared channels enabled.
Basic Information
ID
CVE-2025-9076
Source
Mattermost
Published
Sep 15, 2025 at 10:06
Affected Product
Vendor
Mattermost
Product
Mattermost
Version
10.10.0
Affected Versions
Mattermost Mattermost 10.10.0