Mattermost Plugins API-Level Check Vulnerability Allowing Group Issue Manipulation

Vulnerability

A vulnerability exists in Mattermost Plugins versions 11.5, 11.1.5, 10.13.11, and 11.3.4.0, where API-level checks are insufficient regarding group permissions for issue creation and comment attachment. This flaw enables users who are members of multiple groups to direct API requests to create issues in locked groups. Mattermost Advisory ID: MMSA-2026-00602

Impact

Exploitation of this vulnerability allows for unauthorized issue creation and comment posting in restricted groups, potentially leading to information disclosure or disruption of group activities.

Remediation

Users can upgrade to Mattermost Plugins version 11.7.011.6.211.5.510.11.17 to address this vulnerability.

Added: May 18, 2026, 8:18 AM
Updated: May 18, 2026, 8:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
0.6
exploitability
5.2
remediation
7.7
relevance
8.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.