
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2458 is a missing authorization vulnerability in Mattermost Server that allows a removed team member to enumerate all public channels within a private team via the channel search API endpoint. It affects Mattermost Server versions 10.11.x ≤ 10.11.10, 11.2.x ≤ 11.2.2, and 11.3.x ≤ 11.3.0. The vulnerability was published on March 16, 2026, and is tracked under Mattermost Advisory ID MMSA-2025-00568. It carries a CVSS v3.1 base score of 4.3 (Medium) (Mattermost Security).
The root cause is a failure to properly validate team membership when processing channel search requests, classified as CWE-862 (Missing Authorization). When a user is removed from a team, the channel search API endpoint does not enforce the membership check, allowing the removed user's authenticated session to still query and enumerate public channels belonging to the private team. Exploitation requires only a low-privilege authenticated account, no user interaction, and is achievable remotely over the network with low attack complexity (Mattermost Security).
Successful exploitation results in unauthorized information disclosure — specifically, a removed team member can discover the names and details of all public channels within a private team they no longer have legitimate access to. The impact is limited to confidentiality (low), with no effect on integrity or availability. While the vulnerability does not enable direct data exfiltration or lateral movement, channel enumeration could assist an attacker in mapping an organization's internal communication structure for further social engineering or targeted attacks (Mattermost Security).
/api/v4/teams/{team_id}/channels/search) with a wildcard or broad search query, using the attacker's session token./api/v4/teams/{team_id}/channels/search from accounts that are no longer active team members; unusual volume of channel search API calls from a single user token.Mattermost has released patched versions addressing this vulnerability: upgrade to 10.11.11 or later (for 10.11.x users), 11.2.3 or later (for 11.2.x users), or 11.3.1 or later (for 11.3.x users). As an interim measure if immediate patching is not possible, administrators should review and restrict API access controls at the network level to limit channel search API endpoint exposure, and audit removed team members to ensure their accounts are fully deprovisioned. Reviewing API access logs for enumeration attempts is also recommended (Mattermost Security).
The vulnerability received routine coverage from automated CVE tracking services and security feeds, including mentions on Bluesky CVE tracking accounts and aggregators such as VulnDB and CVEFeed. An openSUSE security announcement was also issued referencing the vulnerability. No notable independent researcher commentary or significant media coverage has been identified beyond standard advisory distribution.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."