CVE-2025-10545

Guest user can add unauthorized team users to private channels

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team members to their private channels via the `/api/v4/channels/{channel_id}/members` endpoint


We have discovered 74 live websites that are affected by CVE-2025-10545.

Run a Free Instant Scan




Affected Software

Product  Mattermost
Category Message Boards
Vulnerable Domains74 live websites (19% of Mattermost install base)
Vulnerable Versions
  • from 10.5 through 10.5.10
  • from 10.11 through 10.11.2
Vulnerable Versions Count8 versions ( 11% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Oct 16, 2025
  • Updated - Oct 16, 2025

Credits

  • lordwillmore (finder)

Website Distribution by Country

Number of websites using CVE-2025-10545
United States12 websites



Germany28 websites
GB9 websites
France8 websites
Russia3 websites
Belgium2 websites
Czech Republic2 websites
Turkmenistan2 websites
Austria1 websites

Website Distribution by TLD

Number of websites using CVE-2025-10545
.com17 websites
.org17 websites
.de10 websites
.ru4 websites
.fr3 websites
.net3 websites
.be2 websites
.co.uk2 websites
.ca1 websites
.co1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-10545

Top websites that are affected by CVE-2025-10545. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com Germany***,***
****.*******.org Germany*,***,***
**.*****.re Germany*,***,***
***********.ru Russia*,***,***
****.*******.com Germany*,***,***
****.*********.org United States*,***,***
*************.org GB*,***,***
****************.de Germany*,***,***
******.de Germany*,***,***
*****.*************.org GB*,***,***
See full domain list

FAQ

CVE-2025-10545 is Incorrect Authorization in Mattermost
A total of 74 websites have been identified as vulnerable to CVE-2025-10545, based on global website indexing conducted by WebTechSurvey.
The Mattermost is affected by the CVE-2025-10545 vulnerability.
Mattermost versions up to and including 10.11.2 are vulnerable to CVE-2025-10545.