CVE-2026-22892: Insufficient Authorization in Mattermost Jira Plugin Allows Unauthorized Access to Post Attachments
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to via the /create-issue API endpoint by providing the post ID of an inaccessible post.. Mattermost Advisory ID: MMSA-2025-00550
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22892?
CVE-2026-22892 is classified as a critical vulnerability due to its potential to allow unauthorized access to sensitive post attachments.
What versions of Mattermost are affected by CVE-2026-22892?
CVE-2026-22892 affects Mattermost versions 11.1.x up to 11.1.2, 10.11.x up to 10.11.9, and 11.2.x up to 11.2.1.
How do I fix CVE-2026-22892?
To mitigate CVE-2026-22892, upgrade Mattermost to the latest version that is not affected by this vulnerability.
What type of attacks can CVE-2026-22892 facilitate?
CVE-2026-22892 can facilitate unauthorized access to post attachments in Mattermost by exploiting insufficient authorization checks.
Is authentication sufficient to protect against CVE-2026-22892?
No, simply being authenticated is not sufficient because CVE-2026-22892 allows attackers to bypass authorization checks.