Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modifications, which allows an authorised attacker with editor permission to modify comments created by other board members. Mattermost Advisory ID: MMSA-2025-00559

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Update Mattermost Plugins to versions 11.4.0, 11.3.1, 11.2.3, 10.11.11 or higher.


Workaround

No workaround given by the vendor.

References
History

Mon, 16 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Mar 2026 11:45:00 +0000

Type Values Removed Values Added
Description Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modifications, which allows an authorised attacker with editor permission to modify comments created by other board members. Mattermost Advisory ID: MMSA-2025-00559
Title Missing authorization check allows unauthorized modification of other users' comments on a board
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-03-16T13:49:57.924Z

Reserved: 2026-02-13T11:09:37.505Z

Link: CVE-2026-2461

cve-icon Vulnrichment

Updated: 2026-03-16T13:44:17.926Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-16T14:19:29.753

Modified: 2026-03-16T14:53:07.390

Link: CVE-2026-2461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses