CVE-2026-2458: Unauthorized channel enumeration in private teams after member removal
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership when searching channels which allows a removed team member to enumerate all public channels within a private team via the channel search API endpoint.. Mattermost Advisory ID: MMSA-2025-00568
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2458?
CVE-2026-2458 is classified as a critical vulnerability due to its potential for unauthorized access to sensitive channel information.
How do I fix CVE-2026-2458?
To mitigate CVE-2026-2458, update Mattermost to versions greater than 11.3.0, 11.2.2, or 10.11.10.
Who is affected by CVE-2026-2458?
CVE-2026-2458 affects users of Mattermost versions 11.3.x up to and including 11.3.0, 11.2.x up to and including 11.2.2, and 10.11.x up to and including 10.11.10.
What type of vulnerability is CVE-2026-2458?
CVE-2026-2458 is an unauthorized channel enumeration vulnerability that affects private teams.
What could happen if CVE-2026-2458 is exploited?
If exploited, CVE-2026-2458 allows a removed team member to enumerate all public channels within a private team, leading to potential data exposure.