Permission Misconfiguration in Mattermost Allows Unauthorized Access
CVE-2026-3113
5MEDIUM
What is CVE-2026-3113?
Multiple versions of Mattermost exhibit a permissions misconfiguration in their bulk export functionality. Specifically, users on the same server can access the contents of bulk exports that they should not have permission to read. This flaw affects Mattermost versions 11.4.x up to and including 11.4.0, 11.3.x up to and including 11.3.1, 11.2.x up to and including 11.2.3, and 10.11.x up to and including 10.11.11. Server administrators must take immediate action to safeguard sensitive data from unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mattermost 11.4.0
Mattermost 11.3.0 <= 11.3.1
Mattermost 11.2.0 <= 11.2.3