Mattermost fails to enforce invite permissions when updating team settings
Low severity
GitHub Reviewed
Published
Feb 16, 2026
to the GitHub Advisory Database
•
Updated Feb 19, 2026
Package
Affected versions
>= 11.1.0, < 11.1.3
>= 10.11.0, < 10.11.10
>= 11.2.0, < 11.2.2
< 5.3.2-0.20251215190648-6404ab29acc0
Patched versions
5.3.2-0.20251215190648-6404ab29acc0
< 8.0.0-20251215190648-6404ab29acc0
8.0.0-20251215190648-6404ab29acc0
Description
Published by the National Vulnerability Database
Feb 16, 2026
Published to the GitHub Advisory Database
Feb 16, 2026
Reviewed
Feb 19, 2026
Last updated
Feb 19, 2026
Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisory ID: MMSA-2025-00561
References