Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to via a race condition in the /common_teams API endpoint.. Mattermost Advisory ID: MMSA-2025-00549

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Update Mattermost to versions 11.3.0, 10.11.10 or higher.


Workaround

No workaround given by the vendor.

References
History

Fri, 13 Feb 2026 10:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to via a race condition in the /common_teams API endpoint.. Mattermost Advisory ID: MMSA-2025-00549
Title Time-of-check time-of-use vulnerability in common teams API
Weaknesses CWE-367
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-02-13T10:30:03.445Z

Reserved: 2026-01-15T11:34:00.225Z

Link: CVE-2026-20796

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-13T11:16:10.280

Modified: 2026-02-13T14:23:48.007

Link: CVE-2026-20796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses