CVE-2026-4274

Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-level access when processing membership sync from a remote cluster, which allows a malicious remote cluster to grant a user access to an entire private team instead of only the shared channel via sending crafted membership sync messages that trigger team membership assignment. Mattermost Advisory ID: MMSA-2026-00574
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:56

Type Values Removed Values Added
Summary
  • (es) Versiones de Mattermost 11.2.x hasta 11.2.2, 10.11.x hasta 10.11.10, 11.4.x hasta 11.4.0, 11.3.x hasta 11.3.1 no restringen el acceso a nivel de equipo al procesar la sincronización de membresía desde un clúster remoto, lo que permite a un clúster remoto malicioso otorgar a un usuario acceso a un equipo privado completo en lugar de solo al canal compartido mediante el envío de mensajes de sincronización de membresía manipulados que desencadenan la asignación de membresía de equipo. ID de Aviso de Mattermost: MMSA-2026-00574

26 Mar 2026, 18:48

Type Values Removed Values Added
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
First Time Mattermost
Mattermost mattermost Server
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory

26 Mar 2026, 11:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 11:16

Updated : 2026-06-17 10:56


NVD link : CVE-2026-4274

Mitre link : CVE-2026-4274

CVE.ORG link : CVE-2026-4274


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-863

Incorrect Authorization