{"id":"CVE-2025-11776","aliases":["GO-2025-4126"],"url":"https://o3.security/vulnerability/CVE-2025-11776","summary":"Mattermost fails to properly restrict access to archived channel search API","details":"Mattermost versions < 11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint","published":"2025-11-14T09:30:27Z","modified":"2025-11-17T19:58:46.484873Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"epss":{"score":0.00192,"percentile":0.08881,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/mattermost/mattermost/server/v8","fixedVersion":"8.0.0-20250815165020-c8d66301415d"},{"ecosystem":"Go","name":"github.com/mattermost/mattermost","fixedVersion":"5.3.2-0.20250815165020-c8d66301415d"},{"ecosystem":"Go","name":"github.com/mattermost/mattermost-server","fixedVersion":"5.3.2-0.20250815165020-c8d66301415d"},{"ecosystem":"Go","name":"github.com/mattermost/mattermost-server/v5","fixedVersion":"5.3.2-0.20250815165020-c8d66301415d"},{"ecosystem":"Go","name":"github.com/mattermost/mattermost-server/v6","fixedVersion":"5.3.2-0.20250815165020-c8d66301415d"}],"fix":{"url":"https://github.com/mattermost/mattermost/commit/c8d66301415d5b447df0e829bdbaa92e8a83ecf8","label":"mattermost/mattermost@c8d6630"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11776"},{"type":"WEB","url":"https://github.com/mattermost/mattermost/commit/c8d66301415d5b447df0e829bdbaa92e8a83ecf8"},{"type":"WEB","url":"https://mattermost.com/security-updates"},{"type":"PACKAGE","url":"github.com/mattermost/mattermost"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-11-17T19:58:46.484873Z"}}