| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fx49-m253-27jj | Mattermost fails to filter invite IDs based on user permissions |
Solution
Update Mattermost to versions 11.4.0, 11.3.1, 11.2.3, 10.11.11 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Wed, 18 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Mon, 16 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs during team creation.. Mattermost Advisory ID: MMSA-2025-00565 | |
| Title | Unauthorized access to invite ID during team creation | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-03-16T13:49:58.332Z
Reserved: 2026-02-13T11:32:02.091Z
Link: CVE-2026-2463
Updated: 2026-03-16T13:44:19.874Z
Status : Analyzed
Published: 2026-03-16T14:19:30.193
Modified: 2026-03-18T17:43:26.553
Link: CVE-2026-2463
No data.
OpenCVE Enrichment
No data.
Github GHSA