Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisory ID: MMSA-2025-00561
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
History
18 Feb 2026, 20:18
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Mattermost
Mattermost mattermost Server |
|
| CPE | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| References | () https://mattermost.com/security-updates - Vendor Advisory |
18 Feb 2026, 17:52
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
16 Feb 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-16 13:16
Updated : 2026-02-18 20:18
NVD link : CVE-2025-14573
Mitre link : CVE-2025-14573
CVE.ORG link : CVE-2025-14573
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-862
Missing Authorization
