Mattermost Search API Permission Vulnerability Allowing Unauthorized Access to Posts and Files

Vulnerability

A vulnerability exists in Mattermost versions 11.3.x prior to 11.3.0, 11.2.x prior to 11.2.2, and 10.11.x prior to 10.11.10. These versions do not properly enforce read permissions in search API endpoints, allowing guest users without read permissions to access posts and files in channels through search API requests.

Impact

Exploitation of this vulnerability allows unauthorized access to posts and files in channels via the search API, bypassing normal read permissions for guest users.

Remediation

Users can upgrade to Mattermost versions 11.5.0, 11.4.0, or 10.11.12 to address this vulnerability.

Added: Mar 16, 2026, 3:38 PM
Updated: Mar 16, 2026, 3:38 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
5.2
remediation
7.7
relevance
4.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.