CVE-2026-26230
EUVD-2026-1251816.03.2026, 21:16
Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API endpoint which allows team administrators to demote members to guest role. Mattermost Advisory ID: MMSA-2025-00531Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mattermost | mattermost | 10.11.0 ≤ 𝑥 ≤ 10.11.10 |
𝑥
= Vulnerable software versions
References