PT-2026-25679 · Mattermost · Mattermost

Omarahmed1

·

Published

2026-03-16

·

Updated

2026-03-16

·

CVE-2026-2463

CVSS v3.1
4.3
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs during team creation.. Mattermost Advisory ID: MMSA-2025-00565

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-2463

Affected Products

Mattermost