Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost to versions 11.4.0, 11.3.1, 11.2.3, 10.11.11 or higher.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cwfj-642j-gfh4 | Mattermost fails to properly enforce read permissions in search API endpoints |
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Wed, 18 Mar 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Server
|
Tue, 17 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Mon, 16 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in search API endpoints which allows guest users without read permissions to access posts and files in channels via search API requests. Mattermost Advisory ID: MMSA-2025-00554 | |
| Title | Guest users can bypass read permissions via search API | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-03-16T18:19:26.675Z
Reserved: 2026-02-13T10:01:31.964Z
Link: CVE-2026-24692
Updated: 2026-03-16T18:19:23.139Z
Status : Analyzed
Published: 2026-03-16T15:16:21.290
Modified: 2026-03-18T13:54:50.950
Link: CVE-2026-24692
No data.
OpenCVE Enrichment
Updated: 2026-03-24T10:50:24Z
Github GHSA