Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 fail to check RestrictSystemAdmin setting if user doesn't have access to ExperimentalSettings which allows a System Manager to access ExperimentSettings when RestrictSystemAdmin is true via System Console.
{
"nvd_published_at": "2025-05-15T16:15:33Z",
"cwe_ids": [
"CWE-863"
],
"github_reviewed_at": "2025-05-17T15:04:07Z",
"severity": "LOW",
"github_reviewed": true
}