Description
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel patch API.. Mattermost Advisory ID: MMSA-2026-00688
Published: 2026-07-13
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows any authenticated ordinary group or direct message member to set the group_constrained flag on a channel through the channel patch API. Because the flag is not appropriately restricted to only public or private channels that support group synchronization, the member can remove all participants from the conversation, effectively ending the channel. This loss of channel membership disrupts communication within the affected channel.

Affected Systems

Mattermost versions 10.11.x up to 10.11.19, 11.6.x up to 11.6.4, and 11.7.x up to 11.7.2 are impacted.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate risk level. The EPSS score of <1% suggests a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. An attacker only needs basic authenticated access to a channel as a regular member and can use the channel patch API to trigger the flaw. No elevated privileges are required, making the vulnerability a realistic threat in environments where ordinary members have unrestricted patch rights.

Generated by OpenCVE AI on August 1, 2026 at 10:47 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.8.0, 11.7.3, 11.6.5, 10.11.20 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to any version 11.8.0, 11.7.3, 11.6.5, 10.11.20 or newer, which contain the patch for group_constrained flag handling.
  • Restrict channel patch permissions so that only authorized roles can modify channel flags, particularly the group_constrained attribute.
  • Identify existing channels where the group_constrained flag may have been set and reset or remove it if unnecessary; monitor API activity for unexpected channel patch operations.

Generated by OpenCVE AI on August 1, 2026 at 10:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 13 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel patch API.. Mattermost Advisory ID: MMSA-2026-00688
Title Ordinary group/direct message member can enable group_constrained and remove all channel participants
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-07-13T13:57:00.893Z

Reserved: 2026-05-29T11:54:45.722Z

Link: CVE-2026-10085

cve-icon Vulnrichment

Updated: 2026-07-13T13:56:57.873Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:00:04Z

Weaknesses