<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 04:45:29 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-1792 — Improper Access Control in Mattermost Channel Member API</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-1792</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Mattermost&lt;/p&gt;
&lt;p&gt;Mattermost versions 10.7.x &amp;lt;= 10.7.0, 10.5.x &amp;lt;= 10.5.3, 9.11.x &amp;lt;= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Mattermost&lt;/p&gt;
&lt;p&gt;Mattermost versions 10.7.x &amp;lt;= 10.7.0, 10.5.x &amp;lt;= 10.5.3, 9.11.x &amp;lt;= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-1792</guid>
    </item>
  </channel>
</rss>
