CVE-2026-22892 is a medium-severity vulnerability affecting Mattermost versions 11.1.x, 10.11.x, and 11.2.x, specifically within the Jira plugin. It allows an authenticated attacker to bypass user permissions and read content and attachments from inaccessible Mattermost channels by exploiting the /create-issue API endpoint with a post ID. The vulnerability has a CVSS score of 4.3 (medium) due to its low attack complexity and potential for unauthorized information disclosure. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.11.0, <= 10.11.9CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 11.1.0, <= 11.1.2CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 11.2.0, <= 11.2.1CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 10.11.0, < 10.11.10CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | ||
>= 11.0.0, < 11.1.3CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.