
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3115 is an authorization bypass vulnerability in Mattermost Server that allows authenticated guest users to enumerate user IDs outside their permitted visibility scope via the group retrieval endpoint. It is tracked under Mattermost Advisory ID MMSA-2026-00594 and was disclosed on March 26, 2026. Affected versions include 11.2.x ≤ 11.2.2, 10.11.x ≤ 10.11.10, 11.3.x ≤ 11.3.1, and 11.4.x ≤ 11.4.0. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is a failure to enforce view restrictions when retrieving group member IDs through the group retrieval API endpoint, classified as CWE-863 (Incorrect Authorization) and CWE-639 (Authorization Bypass Through User-Controlled Key). An authenticated guest user can send requests to the group retrieval endpoint and receive user IDs that should be outside their visibility scope, effectively bypassing the platform's access control model. Exploitation requires only low-privilege network access (a valid guest account) with no user interaction, making it straightforward to abuse in any deployment where guest accounts are enabled (Red Hat Advisory, Red Hat Bugzilla).
Successful exploitation results in unauthorized information disclosure, specifically the enumeration of user IDs that guest accounts should not be able to observe. While there is no direct integrity or availability impact, the exposed user IDs can facilitate reconnaissance, targeted phishing, or social engineering campaigns against other platform users. The vulnerability affects confidentiality at a low level and is limited in scope to the Mattermost server instance, with no evidence of lateral movement capability (Red Hat Advisory).
GET /api/v4/groups/{group_id}/members) for groups the guest user is not a member of or does not have visibility into./api/v4/groups/*/members) for groups outside their membership or channel scope.Mattermost has released patched versions addressing this vulnerability: upgrade to 11.2.3 or later (for 11.2.x), 10.11.11 or later (for 10.11.x), 11.3.2 or later (for 11.3.x), or 11.4.1 or later (for 11.4.x). As an interim workaround, administrators should consider restricting guest account access at the network level or disabling guest accounts entirely if not required. Reviewing audit logs for anomalous group enumeration activity from guest accounts is also recommended (Mattermost Security, Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."