CVE-2026-4265 is a medium-severity vulnerability affecting Mattermost server versions 11.3.0 and earlier, 11.2.2 and earlier, and 10.11.10 and earlier. It allows a guest user to bypass team-specific file upload permissions by reusing file metadata from a permitted team to post files in a restricted team. Rated 4.3 CVSS (Medium), this vulnerability has a low attack complexity and requires low privileges but no user interaction, leading to a low impact on data integrity by allowing unauthorized file posting. There is currently no evidence of active exploitation, nor is public exploit code available on platforms like Metasploit or ExploitDB. Community discussion and media coverage regarding this vulnerability are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.11.0, <= 10.11.10CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 11.2.0, <= 11.2.2CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 11.3.0, <= 11.3.0CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 10.11.0, < 10.11.11CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | ||
>= 11.2.0, < 11.2.3CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.