CVE-2026-2461: Missing authorization check allows unauthorized modification of other users' comments on a board
Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modifications, which allows an authorised attacker with editor permission to modify comments created by other board members. Mattermost Advisory ID: MMSA-2025-00559
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2461?
CVE-2026-2461 is classified as a medium severity vulnerability due to the potential for unauthorized modification of comments.
How do I fix CVE-2026-2461?
To fix CVE-2026-2461, update Mattermost Plugins to versions beyond 11.3, 11.0.3, 11.2.2, and 10.10.11.0.
What impact does CVE-2026-2461 have on Mattermost users?
CVE-2026-2461 allows an attacker with editor permissions to modify comments of other users, compromising the integrity of discussions.
Which Mattermost Plugin versions are affected by CVE-2026-2461?
Mattermost Plugins versions up to and including 11.3, 11.0.3, 11.2.2, and 10.10.11.0 are affected by CVE-2026-2461.
Is there a workaround for CVE-2026-2461 while I wait for a patch?
Currently, there is no documented workaround for CVE-2026-2461, so updating to a patched version is recommended.