Mattermost fails to filter invite IDs based on user permissions
Moderate severity
GitHub Reviewed
Published
Mar 16, 2026
to the GitHub Advisory Database
•
Updated Mar 17, 2026
Package
Affected versions
< 5.3.2-0.20260105134819-cc427af41b2a
>= 10.11.0-rc1, < 10.11.11
>= 11.2.0-rc1, < 11.2.3
>= 11.3.0-rc1, < 11.3.1
Patched versions
5.3.2-0.20260105134819-cc427af41b2a
10.11.11
11.2.3
11.3.1
< 8.0.0-20260105134819-cc427af41b2a
8.0.0-20260105134819-cc427af41b2a
Description
Published by the National Vulnerability Database
Mar 16, 2026
Published to the GitHub Advisory Database
Mar 16, 2026
Reviewed
Mar 17, 2026
Last updated
Mar 17, 2026
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs during team creation. Mattermost Advisory ID: MMSA-2025-00565
References