CVE-2026-4265: Guest user can upload files without permission across teams
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific uploadfile permissions which allows a guest user to post files in channels where they lack uploadfile permission via uploading files in a team where they have permission and reusing the file metadata in a POST request to a different team. Mattermost Advisory ID: MMSA-2025-00553
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4265?
CVE-2026-4265 has a medium severity rating due to the potential unauthorized access by guest users to upload files in restricted channels.
How do I fix CVE-2026-4265?
To fix CVE-2026-4265, upgrade Mattermost to versions 11.3.1, 11.2.3, or 10.11.11 or later.
Who is affected by CVE-2026-4265?
CVE-2026-4265 affects Mattermost instances running versions 11.3.0, 11.2.2, and 10.11.10.
What types of uploads are vulnerable in CVE-2026-4265?
CVE-2026-4265 allows guest users to upload any files in channels where they lack specific upload_file permissions.
What software versions are related to CVE-2026-4265?
CVE-2026-4265 relates to Mattermost versions 11.3.0, 11.2.2, and 10.11.10 or earlier.