CVE-2026-24692

MEDIUM

Guest users can bypass read permissions via search API

Title source: cna
STIX 2.1

Description

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in search API endpoints which allows guest users without read permissions to access posts and files in channels via search API requests. Mattermost Advisory ID: MMSA-2025-00554

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
MMSA-2025-00554
https://mattermost.com/security-updates

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 9.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (10)
mattermost/mattermost 0 - 8.0.0-20260107142155-0481bd1fb045Go
Mattermost/Mattermost 10.11.0 - 10.11.10
Mattermost/Mattermost 10.11.11
Mattermost/Mattermost 11.2.0 - 11.2.2
Mattermost/Mattermost 11.2.3
Mattermost/Mattermost 11.3.0
Mattermost/Mattermost 11.3.1
Mattermost/Mattermost 11.4.0
mattermost/mattermost-server 0 - 5.3.2-0.20260107142155-0481bd1fb045Go
mattermost/mattermost_server 10.11.0 - 10.11.11
Published Mar 16, 2026
Tracked Since Mar 16, 2026