Description
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel to be promoted to a channel admin
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Mattermost to versions 9.7.0, 9.5.4, 9.6.2, 8.1.13 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34453 | Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel to be promoted to a channel admin |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Tue, 30 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Server
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T01:59:49.900Z
Reserved: 2024-05-23T10:57:59.888Z
Link: CVE-2024-31859
Updated: 2024-05-28T15:36:49.990Z
Status : Analyzed
Published: 2024-05-26T14:15:08.907
Modified: 2025-09-30T15:20:13.333
Link: CVE-2024-31859
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:31:08Z
Weaknesses
EUVD