CVE-2025-22449: Mattermost Server
Low severity, CVSS 3.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.
Affected products
- Mattermost Mattermost Server: from 9.11.0, before 9.11.6 (fixed in 9.11.6)
Published 2025-01-09. Last modified 2026-06-17.