
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4274 is an incorrect authorization vulnerability in Mattermost Server that allows a malicious remote cluster to grant users unauthorized access to entire private teams by sending crafted membership sync messages. It affects Mattermost Server versions 10.11.x ≤ 10.11.10, 11.2.x ≤ 11.2.2, 11.3.x ≤ 11.3.1, and 11.4.x ≤ 11.4.0. The vulnerability was disclosed on March 26, 2026, and is tracked under Mattermost Advisory ID MMSA-2026-00574. It carries a CVSS v3.1 base score of 5.4 (Medium) (Mattermost Advisory).
The root cause is an incorrect authorization flaw (CWE-863) in Mattermost's remote cluster membership synchronization logic. When processing membership sync messages from a remote cluster, the server fails to enforce team-level access restrictions, allowing the sync process to assign users to entire private teams rather than limiting access to only the shared channel. An attacker controlling a malicious remote cluster can craft membership sync messages that trigger improper team membership assignment, escalating a user's access beyond what is intended. The attack requires low-privilege credentials and network access but no user interaction (Mattermost Advisory).
Successful exploitation allows unauthorized users to gain access to private teams, including all channels, messages, files, and communications within those teams. This results in confidentiality and integrity impacts — sensitive team data may be exposed to unauthorized parties, and team membership state is improperly modified. The vulnerability does not affect availability. Organizations using Mattermost's federated/shared channel features with remote clusters are most at risk, as the attack vector is the inter-cluster synchronization mechanism (Mattermost Advisory).
Mattermost has released patched versions addressing this vulnerability: 10.11.11, 11.2.3, 11.3.2, and 11.4.1. Administrators should upgrade to the appropriate patched version for their release branch as the primary remediation. If immediate patching is not feasible, restrict network access to remote cluster synchronization endpoints and limit federation to trusted clusters only. Additionally, audit current private team memberships to identify any unauthorized access that may have already occurred, and implement network segmentation to limit communication with untrusted remote clusters (Mattermost Advisory).
The vulnerability received routine coverage in CVE tracking feeds and vulnerability databases shortly after disclosure on March 26, 2026. There was minimal notable commentary from the broader security research community, consistent with the medium severity rating and absence of public exploit code. A brief mention appeared on Bluesky via automated CVE notification accounts (Mattermost Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."