- Description
 - Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to restrict channel export of archived channels when the "Allow users to view archived channels" is disabled which allows a user to export channel contents when they shouldn't have access to it
 - Source
 - responsibledisclosure@mattermost.com
 - NVD status
 - Analyzed
 - Products
 - mattermost_server
 
CVSS 3.1
- Type
 - Secondary
 - Base score
 - 4.3
 - Impact score
 - 1.4
 - Exploitability score
 - 2.8
 - Vector string
 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
 - Severity
 - MEDIUM
 
- responsibledisclosure@mattermost.com
 - CWE-863
 
- Hype score
 - Not currently trending
 
CVE-2025-24526 Privilege Escalation in Mattermost Channel Export Functionality Across Multiple Versions https://t.co/u2goov9huQ
@VulmonFeeds
24 Feb 2025
49 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
CVE-2025-24526 Mattermost versions 10.1.x <= 10.1.3, 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to restrict channel export of archived channels when… https://t.co/P3sXcSupNN
@CVEnew
24 Feb 2025
520 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
  {
    "nodes": [
      {
        "negate": false,
        "cpeMatch": [
          {
            "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "3E229B1F-4D4B-405D-ADAF-831AD561DDE0",
            "versionEndExcluding": "9.11.8",
            "versionStartIncluding": "9.11.0"
          },
          {
            "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "C9D87A5B-2D40-446B-B9FB-4376B846432F",
            "versionEndExcluding": "10.1.4",
            "versionStartIncluding": "10.1.0"
          },
          {
            "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "EDC47726-A40F-4485-9DBD-D0E23526BFC6",
            "versionEndExcluding": "10.2.3",
            "versionStartIncluding": "10.2.0"
          },
          {
            "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "4B08BF27-E86F-472D-B91C-776E7D9425CB",
            "versionEndExcluding": "10.3.3",
            "versionStartIncluding": "10.3.0"
          },
          {
            "criteria": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "20456526-878A-4CEA-A563-0D9878ED300C",
            "versionEndExcluding": "10.4.2",
            "versionStartIncluding": "10.4.0"
          }
        ],
        "operator": "OR"
      }
    ]
  }
]