
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2463 is a missing authorization vulnerability in Mattermost Server that allows authenticated low-privileged users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs during team creation. It affects Mattermost Server versions 10.11.0–10.11.10, 11.2.0–11.2.2, and 11.3.0. The vulnerability was published on March 16, 2026, and is tracked under Mattermost Advisory ID MMSA-2025-00565. It carries a CVSS v3.1 base score of 4.3 (Medium) (Mattermost Security, ENISA EUVD).
The root cause is classified as CWE-862 (Missing Authorization): Mattermost fails to filter invite IDs based on the requesting user's permissions, meaning any authenticated user who obtains a team invite ID can use it to register new accounts regardless of whether they are authorized to do so. The attack vector is network-based, requires low privileges (an existing authenticated account), no user interaction, and low attack complexity. Invite IDs can be leaked during the team creation process, and once obtained, a malicious user can submit them to register accounts that would otherwise be restricted (Mattermost Security, ENISA EUVD).
Successful exploitation allows an attacker with basic user privileges to register unauthorized accounts within Mattermost teams, potentially gaining access to team channels, messages, files, and other resources that should be restricted. The confidentiality impact is limited (low), with no direct integrity or availability impact. However, unauthorized account creation could facilitate insider-threat scenarios, data exposure, or serve as a foothold for further lateral movement within an organization's collaboration environment (Mattermost Security, ENISA EUVD).
mattermost.log for team join events from users who should not have access.Mattermost has released patched versions addressing this vulnerability: 10.11.11 (for the 10.11.x branch), 11.2.3 (for the 11.2.x branch), and 11.3.1 (for the 11.3.x branch). Organizations should upgrade to one of these versions immediately. As additional hardening steps, administrators should audit existing team invite IDs and revoke any that may have been exposed, review account creation and team membership logs for unauthorized accounts created during the vulnerable window, and restrict invite ID visibility to authorized administrators only (Mattermost Security, ENISA EUVD).
Coverage of CVE-2026-2463 has been limited to automated vulnerability tracking platforms and security feeds, with no notable researcher commentary or significant media coverage identified. The vulnerability was noted on Bluesky via automated CVE tracking accounts and indexed by standard vulnerability databases shortly after publication (ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."