A vulnerability, which was classified as problematic, has been found in Mattermost up to 10.11.10/11.3.x. This affects an unknown part of the component API Endpoint. This manipulation causes incorrect authorization.

This vulnerability is handled as CVE-2026-26230. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.