
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24692 is an incorrect authorization vulnerability in Mattermost Server that allows authenticated guest users to bypass read permission restrictions and access posts and files in channels they are not authorized to view via search API endpoints. It affects Mattermost Server versions 11.3.x ≤ 11.3.0, 11.2.x ≤ 11.2.2, and 10.11.x ≤ 10.11.10. The vulnerability was published on March 16, 2026, and is tracked under Mattermost Advisory ID MMSA-2025-00554. It carries a CVSS v3.1 base score of 4.3 (Medium) (Mattermost Security Updates, Feedly).
The root cause is improper enforcement of read permissions in Mattermost's search API endpoints, classified as CWE-863 (Incorrect Authorization). When a guest user submits a search API request, the server fails to validate whether that user has read access to the channels being searched, returning posts and files from restricted channels. Exploitation requires only a valid low-privilege (guest) account and network access to the Mattermost instance — no special configuration or user interaction is needed. No public proof-of-concept code has been identified at this time (Feedly, Mattermost Security Updates).
Successful exploitation allows guest users to read sensitive channel content — including posts and attached files — from channels they have not been granted access to, resulting in unauthorized information disclosure. The confidentiality impact is limited to content accessible via the search API, with no integrity or availability impact. In environments where Mattermost channels contain confidential business communications, credentials, or sensitive files, this could lead to meaningful data exposure for any organization using guest accounts (Feedly).
POST /api/v4/posts/search) with a search query targeting content in channels the guest account does not have read access to./api/v4/posts/search or similar Mattermost search API endpoints originating from guest user accounts.Mattermost has released patched versions addressing this vulnerability: upgrade to 11.3.1 (for 11.3.x deployments), 11.2.3 (for 11.2.x deployments), or 10.11.11 (for 10.11.x deployments). As a temporary workaround prior to patching, administrators should consider restricting or disabling guest user access to search functionality, or disabling guest accounts entirely if not required. Reviewing audit logs for unauthorized search API activity by guest accounts is also recommended (Mattermost Security Updates, Feedly).
The vulnerability received routine coverage from automated vulnerability tracking services and security news aggregators shortly after disclosure. An openSUSE security announcement and a Linux Security advisory were published referencing the issue in the context of package updates. No notable researcher commentary or significant community discussion has been identified beyond standard CVE tracking (openSUSE Security Announce, Linux Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."