CVE-2026-22892 PUBLISHED

Insufficient Authorization in Mattermost Jira Plugin Allows Unauthorized Access to Post Attachments

Assigner: Mattermost
Reserved: 15.01.2026 Published: 13.02.2026 Updated: 13.02.2026

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to via the /create-issue API endpoint by providing the post ID of an inaccessible post.. Mattermost Advisory ID: MMSA-2025-00550

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor Mattermost
Product Mattermost
Versions Default: unaffected
  • affected from 11.1.0 to 11.1.2 (incl.)
  • affected from 10.11.0 to 10.11.9 (incl.)
  • affected from 11.2.0 to 11.2.1 (incl.)
  • Version 11.3.0 is unaffected
  • Version 11.1.3 is unaffected
  • Version 10.11.10 is unaffected
  • Version 11.2.2 is unaffected

Solutions

Update Mattermost to versions 11.3.0, 11.1.3, 10.11.10, 11.2.2 or higher.

Credits

  • Juho Forsén finder

References

Problem Types

  • CWE-863: Incorrect Authorization CWE