CVE-2026-5163: Mattermost Server
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites which allows an authenticated attacker to read the content of threads in private channels and direct messages they do not have access to via a crafted request to the post rewrite endpoint.. Mattermost Advisory ID: MMSA-2026-00645
Affected products
- Mattermost Mattermost Server: from 11.5.0, before 11.5.2 (fixed in 11.5.2)
Published 2026-05-18. Last modified 2026-06-17.