CVE-2026-2463: Unauthorized access to invite ID during team creation
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs during team creation.. Mattermost Advisory ID: MMSA-2025-00565
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2463?
CVE-2026-2463 is a high severity vulnerability due to unauthorized access and permission bypass.
How do I fix CVE-2026-2463?
To fix CVE-2026-2463, upgrade to Mattermost versions higher than 11.3.0, 11.2.2, or 10.11.10.
What types of software are affected by CVE-2026-2463?
CVE-2026-2463 affects Mattermost versions 11.3.x up to and including 11.3.0, 11.2.x up to and including 11.2.2, and 10.11.x up to and including 10.11.10.
What kind of attacks can result from CVE-2026-2463?
CVE-2026-2463 can allow regular users to register unauthorized accounts through leaked invite IDs.
Who is impacted by CVE-2026-2463?
Users of Mattermost who are on affected versions risk unauthorized account registrations and access due to CVE-2026-2463.