PT-2026-25679 · Mattermost · Mattermost

Omarahmed1

·

Published

2026-02-13

·

Updated

2026-03-27

·

CVE-2026-2463

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 10.11.0 through 10.11.10 Mattermost versions 11.2.0 through 11.2.2 Mattermost versions 11.3.0
Description Mattermost does not properly filter invite IDs based on user permissions. This allows regular users to bypass access control restrictions and register unauthorized accounts using leaked invite IDs during team creation.
Recommendations Update Mattermost to a version later than 10.11.10. Update Mattermost to a version later than 11.2.2. Update Mattermost to a version later than 11.3.0.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-06573
CVE-2026-2463
GHSA-FX49-M253-27JJ
GO-2026-4735
SUSE-SU-2026:1135-1

Affected Products

Mattermost