CVE-2026-6341: Incomplete group locking implementation
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to have API-level checks on which groups the user can create issues or attach comments to which allows a user that is member of multiple groups to create issues to a locked group via direct API requests. Mattermost Advisory ID: MMSA-2026-00602
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermost Pluginsto a version that resolves this vulnerability.Fixed in 11.6.0 - Upgrade
Upgrade
Mattermost Pluginsto a version that resolves this vulnerability.Fixed in 11.5.2 - Upgrade
Upgrade
Mattermost Pluginsto a version that resolves this vulnerability.Fixed in 10.11.14 - Upgrade
Upgrade
Mattermost Pluginsto a version that resolves this vulnerability.Fixed in 11.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6341?
CVE-2026-6341 is classified as a medium severity vulnerability due to its potential to allow unauthorized issue creation in locked groups.
How do I fix CVE-2026-6341?
To fix CVE-2026-6341, upgrade to Mattermost Plugins version 11.5 or later, or ensure proper API-level checks are implemented.
What are the affected versions in CVE-2026-6341?
CVE-2026-6341 affects Mattermost Plugins versions up to and including 11.5, 11.1.5, 10.13.11, and 11.3.4.0.
What type of vulnerability is CVE-2026-6341?
CVE-2026-6341 is an incomplete group locking implementation vulnerability that affects user permissions in Mattermost Plugins.
How can CVE-2026-6341 affect my Mattermost deployment?
CVE-2026-6341 can allow users to create issues or comments in groups that are supposed to be locked, potentially leading to unauthorized access or information exposure.