
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14573 is a missing authorization vulnerability in Mattermost Server that allows team administrators without proper invite permissions to bypass restrictions and add users to their team via API requests. It affects Mattermost Server versions 10.11.0 through 10.11.9 (inclusive), and is tracked under Mattermost Advisory ID MMSA-2025-00561. The vulnerability was published on February 16, 2026, with a patch released in version 10.11.10. It carries a CVSS v3.1 base score of 2.7 (Low) (Red Hat CVE, Mattermost Security).
The root cause is classified as CWE-862 (Missing Authorization): Mattermost Server fails to enforce invite permission checks when processing API requests that update team settings, specifically the allowOpenInvite field. A team administrator — who would otherwise lack the privilege to invite users — can craft API requests to modify team settings and add users, bypassing the intended permission model. No authentication bypass is required; the attacker must already hold a team administrator role, making this an authorization enforcement gap rather than an authentication flaw (Red Hat CVE, Infinitsec).
Exploitation allows a team administrator without proper invite permissions to add unauthorized users to a Mattermost team, resulting in unauthorized access to team channels, messages, files, and other shared resources. The integrity impact is limited to team membership modification, with no direct confidentiality or availability impact assessed. While lateral movement potential is low, unauthorized team membership could expose sensitive organizational communications to unintended parties (Red Hat CVE).
PUT /api/v4/teams/{team_id}) with the allow_open_invite or related invite permission field set to enable open invitations, bypassing server-side permission enforcement.PUT /api/v4/teams/{team_id} requests from team administrator accounts that modify invite-related settings (allow_open_invite) without corresponding system administrator authorization.Mattermost has released a patch in version 10.11.10, which enforces proper invite permission checks during team settings updates. Organizations should upgrade Mattermost Server to version 10.11.10 or later immediately. As interim measures, administrators should review team administrator permissions, audit recent team membership changes for unauthorized additions, and monitor API requests related to team settings updates for suspicious activity (Mattermost Security, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."