LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-24692

mattermost · mattermost server

Published
CVSS4.3
Severitymedium
WeaknessCWE-863
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in search API endpoints which allows guest users without read permissions to access posts and files in channels via search API requests. Mattermost Advisory ID: MMSA-2025-00554

References

← Back to the CVE Tracker

Our coverage of CVE-2026-24692

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-24692.