CVE-2024-29221: Mattermost Server

Low severity, CVSS 3.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Access Control in Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 lacked proper access control in the `/api/v4/users/me/teams` endpoint allowing a team admin to get the invite ID of their team, thus allowing them to invite users, even if the "Add Members" permission was explicitly removed from team admins.

Affected products

  • Mattermost Mattermost Server: from 8.1.0, before 8.1.11 (fixed in 8.1.11); from 9.3.0, before 9.3.3 (fixed in 9.3.3); from 9.4.0, before 9.4.4 (fixed in 9.4.4); from 9.5.0, before 9.5.2 (fixed in 9.5.2)

Published 2024-04-05. Last modified 2026-06-17.