Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the OAuth state.
{
"github_reviewed": true,
"github_reviewed_at": "2025-10-16T21:10:20Z",
"nvd_published_at": "2025-10-16T09:15:34Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-862"
]
}