Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in search API endpoints which allows guest users without read permissions to access posts and files in channels via search API requests. Mattermost Advisory ID: MMSA-2025-00554
References
History

Mon, 16 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in search API endpoints which allows guest users without read permissions to access posts and files in channels via search API requests. Mattermost Advisory ID: MMSA-2025-00554
Title Guest users can bypass read permissions via search API
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-03-16T14:56:45.323Z

Reserved: 2026-02-13T10:01:31.964Z

Link: CVE-2026-24692

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-16T15:16:21.290

Modified: 2026-03-16T15:16:21.290

Link: CVE-2026-24692

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.