GHSA-h69v-mvh9-hfrq
GitHub Security Advisory
Mattermost Incorrect Authorization vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager
Affected Packages
Go
github.com/mattermost/mattermost/server/v8
Affected versions:
8.1.0
(fixed in 8.1.1)
Go
github.com/mattermost/mattermost/server/v8
Affected versions:
8.0.0
(fixed in 8.0.2)
Go
github.com/mattermost/mattermost-server/v6
Affected versions:
0
(fixed in 7.8.10)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 2, 2025 6:46 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.