Generated remediation guidance and an executive summary. No account required.
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restrictions when retrieving group member IDs, which allows authenticated guest users to enumerate user IDs outside their allowed visibility scope via the group retrieval endpoint.. Mattermost Advisory ID: MMSA-2026-00594
Cite this page
CVE-2026-3115. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-3115
Use CWE-863, Mattermost vendor hub and Mattermost Server product page to widen CVE-2026-3115 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-3108, CVE-2026-28741 and CVE-2026-3112 for nearby disclosures in the same product family.