PT-2026-25759 · Mattermost · Mattermost
0X7Oda7123
·
Published
2026-03-16
·
Updated
2026-03-16
·
CVE-2026-24692
CVSS v3.1
4.3
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in search API endpoints which allows guest users without read permissions to access posts and files in channels via search API requests. Mattermost Advisory ID: MMSA-2025-00554
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mattermost