Back

MEDIUM

Guest user can upload files without permission across teams

Published Mar 16, 2026

Description

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in channels where they lack upload_file permission via uploading files in a team where they have permission and reusing the file metadata in a POST request to a different team. Mattermost Advisory ID: MMSA-2025-00553

Affected products

Remediation

Vendor solution

Update Mattermost to versions 11.4.0, 11.3.1, 11.2.3, 10.11.11 or higher.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published Mar 16, 2026
Updated Mar 16, 2026
Reserved Mar 16, 2026
CISA Vulnrichment
Updated Mar 16, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Mattermost
Published Mar 16, 2026
Updated Mar 16, 2026
Exploited since n/a
EUVD-2026-12425 GHSA-XPVF-6QCC-9JQC