{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-3115","assignerOrgId":"9302f53e-dde5-4bf3-b2f2-a83f91ac0eee","state":"PUBLISHED","assignerShortName":"Mattermost","dateReserved":"2026-02-24T11:06:52.132Z","datePublished":"2026-03-26T16:23:05.887Z","dateUpdated":"2026-03-26T17:51:14.689Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Mattermost","vendor":"Mattermost","versions":[{"lessThanOrEqual":"11.2.2","status":"affected","version":"11.2.0","versionType":"semver"},{"lessThanOrEqual":"10.11.10","status":"affected","version":"10.11.0","versionType":"semver"},{"lessThanOrEqual":"11.4.0","status":"affected","version":"11.4.0","versionType":"semver"},{"lessThanOrEqual":"11.3.1","status":"affected","version":"11.3.0","versionType":"semver"},{"version":"11.5.0","status":"unaffected"},{"version":"11.2.3","status":"unaffected"},{"version":"10.11.11","status":"unaffected"},{"version":"11.4.1","status":"unaffected"},{"version":"11.3.2","status":"unaffected"}]}],"credits":[{"lang":"en","type":"finder","value":"winfunc"}],"descriptions":[{"lang":"en","value":"Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restrictions when retrieving group member IDs, which allows authenticated guest users to enumerate user IDs outside their allowed visibility scope via the group retrieval endpoint.. Mattermost Advisory ID: MMSA-2026-00594"}],"metrics":[{"cvssV3_1":{"attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseSeverity":"MEDIUM","baseScore":4.3},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"lang":"en","type":"CWE","description":"CWE-863: Incorrect Authorization","cweId":"CWE-863"}]}],"references":[{"url":"https://mattermost.com/security-updates","name":"MMSA-2026-00594","tags":["vendor-advisory"]}],"solutions":[{"value":"Update Mattermost to versions 11.5.0, 11.2.3, 10.11.11, 11.4.1, 11.3.2 or higher.","lang":"en"}],"source":{"advisory":"MMSA-2026-00594","defect":["https://mattermost.atlassian.net/browse/MM-67354"],"discovery":"EXTERNAL"},"title":"Guest users can view group member IDs without respecting view restrictions","providerMetadata":{"orgId":"9302f53e-dde5-4bf3-b2f2-a83f91ac0eee","shortName":"Mattermost","dateUpdated":"2026-03-26T16:23:05.887Z"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2026-3115","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2026-03-26T17:37:24.982329Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-03-26T17:51:14.689Z"}}]}}