CVE-2025-11777

Cross-team channel membership access

Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint


We have discovered 90 live websites that are affected by CVE-2025-11777.

Run a Free Instant Scan




Affected Software

Product  Mattermost
Category Message Boards
Vulnerable Domains90 live websites (23% of Mattermost install base)
Vulnerable Versions
  • from 10.5 through 10.5.11
  • from 10.11 through 10.11.3
Vulnerable Versions Count10 versions ( 14% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Nov 13, 2025
  • Updated - Nov 13, 2025

Credits

  • Xiangyu Guo (finder)

Website Distribution by Country

Number of websites using CVE-2025-11777
United States15 websites



Germany32 websites
France11 websites
GB10 websites
Russia4 websites
Argentina2 websites
Belgium2 websites
Czech Republic2 websites
Turkmenistan2 websites

Website Distribution by TLD

Number of websites using CVE-2025-11777
.com18 websites
.org18 websites
.de14 websites
.fr5 websites
.ru4 websites
.net3 websites
.be2 websites
.co.uk2 websites
.ca1 websites
.co1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-11777

Top websites that are affected by CVE-2025-11777. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com Germany***,***
****.*******.com GB***,***
****.*******.org Germany*,***,***
**.*****.re Germany*,***,***
***********.ru Russia*,***,***
****.*******.com Germany*,***,***
****.*********.org United States*,***,***
*************.org GB*,***,***
****************.de Germany*,***,***
******.de Germany*,***,***
See full domain list

FAQ

CVE-2025-11777 is Incorrect Authorization in Mattermost
A total of 90 websites have been identified as vulnerable to CVE-2025-11777, based on global website indexing conducted by WebTechSurvey.
The Mattermost is affected by the CVE-2025-11777 vulnerability.
Mattermost versions up to and including 10.11.3 are vulnerable to CVE-2025-11777.