Back

MEDIUM

System Role with edit access to permissions can elevate themselves to system admin

Published Aug 22, 2024

Description

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to include the `manage_system` permission, effectively becoming a System Admin.

Affected products

Remediation

Vendor solution

Update Mattermost to versions 9.11.0, 9.9.2, 9.5.8, 9.10.1, 9.8.3 or higher.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published Aug 22, 2024
Updated Aug 22, 2024
Reserved Aug 22, 2024
CISA Vulnrichment
Updated Aug 22, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Mattermost
Published Aug 22, 2024
Updated Aug 22, 2024
Exploited since n/a
EUVD-2024-2499 GHSA-5263-PM2H-M7HW