Project Subscriptions
No data.
No advisories yet.
Solution
Update Mattermost to versions 11.5.0, 11.2.3, 10.11.11, 11.4.1, 11.3.2 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Thu, 26 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restrictions when retrieving group member IDs, which allows authenticated guest users to enumerate user IDs outside their allowed visibility scope via the group retrieval endpoint.. Mattermost Advisory ID: MMSA-2026-00594 | |
| Title | Guest users can view group member IDs without respecting view restrictions | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-03-26T17:51:14.689Z
Reserved: 2026-02-24T11:06:52.132Z
Link: CVE-2026-3115
Updated: 2026-03-26T17:47:18.656Z
Status : Received
Published: 2026-03-26T17:16:42.660
Modified: 2026-03-26T17:16:42.660
Link: CVE-2026-3115
No data.
OpenCVE Enrichment
No data.