CVE-2026-2461: Mattermost Server
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modifications, which allows an authorised attacker with editor permission to modify comments created by other board members. Mattermost Advisory ID: MMSA-2025-00559
Affected products
- Mattermost Mattermost Server: before 10.11.11 (fixed in 10.11.11); from 11.0.0, up to and including 11.0.3; from 11.1.0, before 11.2.3 (fixed in 11.2.3); from 11.3.0, before 11.3.1 (fixed in 11.3.1)
Published 2026-03-16. Last modified 2026-06-17.