CVE-2024-1888: Mattermost Server
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server
Affected products
- Mattermost Mattermost Server: before 8.1.9 (fixed in 8.1.9); from 9.2.0, before 9.2.5 (fixed in 9.2.5); from 9.3.0, before 9.3.1 (fixed in 9.3.1); from 9.4.0, before 9.4.2 (fixed in 9.4.2)
Published 2024-02-29. Last modified 2026-06-17.