Junglewise Threat Intelligence

CVE-2026-5163: Mattermost missing authorization in AI-assisted message rewrites

CVE-2026-5163 · Severity: medium · CVSS 6.5 · Published 2026-05-18

Technologies: github.com/mattermost/mattermost-server/v5 (Go), github.com/mattermost/mattermost-server/v6 (Go), Mattermost Server, github.com/mattermost/mattermost/server/v8 (Go), github.com/mattermost/mattermost-server (Go). Vendors: Go, Mattermost.

Executive brief

Mattermost is a collaboration platform used for team communication and messaging. A security flaw in its AI-assisted message rewriting feature allows a logged-in user to read messages in private channels or direct messages they are not supposed to see. This could lead to the exposure of sensitive corporate data or private conversations to unauthorized employees.

Technical details

A missing authorization check (CWE-862) exists in the Mattermost post rewrite endpoint. When processing AI-assisted message rewrites, the server fails to validate if the requesting user has membership in the channel associated with the 'root_id' of the thread. An authenticated attacker can exploit this by sending a crafted request to the '/posts/rewrite' endpoint to retrieve the content of threads in private channels or direct messages they do not have access to. The vulnerability has been patched in version 11.5.2 and specific backported versions.

Affected products

  • Mattermost Mattermost Server >= 11.5.0, < 11.5.2
  • Mattermost Mattermost Server < 8.0.0-20260401090745-f4d1abe7e8f5

Timeline

  • 2026-04-01: patched: Fix committed to repository
  • 2026-05-18: disclosed: CVE-2026-5163 published
  • 2026-05-18: advisory: GitHub Advisory GHSA-8r89-8w26-cq32 published

References

Related threats