CVE-2026-5163: Missing authorization check in AI message rewrite endpoint allows access to private thread content
Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites which allows an authenticated attacker to read the content of threads in private channels and direct messages they do not have access to via a crafted request to the post rewrite endpoint.. Mattermost Advisory ID: MMSA-2026-00645
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5163?
CVE-2026-5163 is classified as a high severity vulnerability due to the potential exposure of private thread content.
How do I fix CVE-2026-5163?
To fix CVE-2026-5163, upgrade to Mattermost version 11.5.2 or later, where the missing authorization check is addressed.
What does CVE-2026-5163 affect?
CVE-2026-5163 affects Mattermost versions 11.5.0 through 11.5.1, specifically in the AI message rewrite endpoint.
Who can exploit CVE-2026-5163?
Authenticated attackers can exploit CVE-2026-5163 to gain unauthorized access to private thread content.
What is the impact of CVE-2026-5163?
The impact of CVE-2026-5163 is the potential disclosure of sensitive information from private channels to unauthorized users.