CVE-2025-3913 | Mattermost up to 9.11.12/10.5.3/10.6.2/10.7.0 Team Privacy Setting /api/v4/teams/ authorization (Nessus ID 237904)
A vulnerability described as problematic has been identified in Mattermost up to 9.11.12/10.5.3/10.6.2/10.7.0. This affects an unknown part of the file /api/v4/teams/ of the component Team Privacy Setting Handler. Such manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2025-3913. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.