CVE-2026-5163
medium
CVSS v3
6.5
CVSS v2
—
VIR risk
6.5
Description
Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites which allows an authenticated attacker to read the content of threads in private channels and direct messages they do not have access to via a crafted request to the post rewrite endpoint.. Mattermost Advisory ID: MMSA-2026-00645
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: responsibledisclosure@mattermost.com — https://mattermost.com/security-updates
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| mattermost | mattermost_server | {"startIncluding":"11.5.0","endExcluding":"11.5.2"} | 11.5.2 |
References
CWEs
CWE-862
Verify integrity in audit chain (admin only). AS-IS.