CVE-2025-4128 is a medium-severity access control bypass vulnerability affecting Mattermost versions 10.5.x up to 10.5.4 and 9.11.x up to 9.11.13. It allows authenticated guest users to view public team information they are not members of by directly accessing a specific API endpoint. The CVSS score is 4.3, indicating low impact on confidentiality and no impact on integrity or availability, with a low attack complexity and no user interaction required. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.11.0, < 9.11.14CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | ||
>= 10.5.0, < 10.5.5CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | ||
>= 10.5.0, <= 10.5.4CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 9.11.0, <= 9.11.13CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.