Vulnerability Details CVE-2026-6341
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to have API-level checks on which groups the user can create issues or attach comments to which allows a user that is member of multiple groups to create issues to a locked group via direct API requests. Mattermost Advisory ID: MMSA-2026-00602
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 9.4%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2026-6341
-
cpe:2.3:a:mattermost:mattermost_server:*
-
cpe:2.3:a:mattermost:mattermost_server:11.1.0
-
cpe:2.3:a:mattermost:mattermost_server:11.1.1
-
cpe:2.3:a:mattermost:mattermost_server:11.1.2
-
cpe:2.3:a:mattermost:mattermost_server:11.1.3
-
cpe:2.3:a:mattermost:mattermost_server:11.3.0
-
cpe:2.3:a:mattermost:mattermost_server:11.3.1
-
cpe:2.3:a:mattermost:mattermost_server:11.3.2
-
cpe:2.3:a:mattermost:mattermost_server:11.3.3