CVE-2026-2458 | Mattermost up to 10.11.10/11.2.2/11.3.0 API Endpoint authorization
A vulnerability labeled as problematic has been found in Mattermost up to 10.11.10/11.2.2/11.3.0. Affected by this issue is some unknown functionality of the component API Endpoint. Such manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2026-2458. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.