
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4265 is an incorrect authorization vulnerability in Mattermost Server that allows guest users to bypass team-specific file upload restrictions. Affected versions include 11.3.x ≤ 11.3.0, 11.2.x ≤ 11.2.2, and 10.11.x ≤ 10.11.10. The vulnerability was published on March 16, 2026, and is tracked under Mattermost Advisory ID MMSA-2025-00553. It carries a CVSS v3.1 base score of 4.3 (Medium) (Mattermost Security).
The root cause is an incorrect authorization check (CWE-863) in Mattermost's file upload permission validation logic, which fails to enforce team-specific upload_file permissions. An authenticated guest user can exploit this by first uploading a file in a team where they hold upload_file permission, then reusing the resulting file metadata in a POST request targeting a different team's channel where they lack that permission. This cross-team metadata reuse bypasses the intended access control boundary, requiring only low-privilege network access with no user interaction (Mattermost Security).
Successful exploitation allows guest users to post files in channels where they are explicitly denied upload_file permission, undermining channel-level access controls. This could enable guests to share inappropriate, malicious, or sensitive content in restricted channels, compromising the integrity of team and channel boundaries. There is no confidentiality or availability impact; the effect is limited to unauthorized integrity modification of channel content (Mattermost Security).
upload_file permission in at least one team (Team A).file_id).upload_file permission.file_id obtained from Team A in the request body.upload_file permission; file IDs appearing in posts across multiple teams from the same guest account./api/v4/posts in Team B channels shortly after file upload API calls (/api/v4/files) to Team A channels, originating from the same source IP.file_id appears in posts across different teams.Mattermost has released patched versions addressing this vulnerability: 10.11.11, 11.2.3, and 11.3.1. Organizations should immediately upgrade their Mattermost Server instances to one of these versions depending on their current release branch. No configuration-based workaround is documented; upgrading is the recommended remediation. Post-patch, administrators should review audit logs for suspicious cross-team file upload activity by guest users to identify any prior exploitation (Mattermost Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."