CVE-2026-22892Disclosure(mattermost / mattermost_server)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to via the /create-issue API endpoint by providing the post ID of an inaccessible post.. Mattermost Advisory ID: MMSA-2025-00550

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mattermost_server

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-13); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
mattermost_server

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-13: 2Mentions · 2026-02-14: 1Technical Details · 2026-02-13: 2Technical Details · 2026-02-14: 102-1302-14
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-132
Disclosure2
2026-02-141
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-22892 Mattermost versions 11.1.x &lt;= 11.1.2, 10.11.x &lt;= 10.11.9, 11.2.x &lt;= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which al… https://www.cve.org/CVERecord?id=CVE-2026-22892

    Post summary

    CVE‑2026‑22892 allows improper permission validation when creating Jira issues from Mattermost posts, affecting several Mattermost version ranges.

    00031423
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-22892: Confused Deputy in the Chatroom: Dissecting CVE-2026-22892 Mattermost is the fortress of secure collaboration, and Jira is the labyrinth of project management. When you bridge the two, you expect a secure tunnel, not a porous sieve. CV... https://cvereports.com/reports/CVE-2026-22892

    Post summary

    The post introduces CVE-2026-22892 as a Confused Deputy issue between Mattermost and Jira, but offers no exploit code, patches, or evidence of active use.

    0000042
    26 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22892 Mattermost Jira Plugin Privilege Escalation via Unauthorized Post Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22892

    Post summary

    The post references CVE-2026-22892, describing a privilege escalation vulnerability in the Mattermost Jira Plugin, but provides no proof-of-concept, exploit, or remediation details.

    0000037
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmattermostmattermost_server---

Explore more