Insecure Access Control in Mattermost Product by Mattermost
CVE-2026-5163

6.5MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
18 May 2026

What is CVE-2026-5163?

Versions 11.5.x up to 11.5.1 of Mattermost contain a vulnerability where the system fails to properly verify channel membership when handling AI-assisted message rewrites. This oversight enables an authenticated attacker to craft unauthorized requests that can expose the content of private channels and direct messages, bypassing access restrictions. Users should take necessary precautions to secure their Mattermost instances against potential exploitation.

Affected Version(s)

Mattermost 11.5.0 <= 11.5.1

Mattermost 11.6.0

Mattermost 11.5.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daw10
.