Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data Retention Policy permission to obtain a private team's secret invite_id and email, and use it to join the team without authorization, via GET /api/v4/data_retention/policies/{policy_id}/teams.. Mattermost Advisory ID: MMSA-2026-00702
Published: 2026-09-14
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access to Private Team via Exposed Invite ID
Action: Patch
AI Analysis

Impact

This vulnerability occurs when Mattermost incorrectly exposes sensitive team details through the data retention teams endpoint. An authenticated user who only has the read‑only Data Retention Policy permission can retrieve the team's secret invite_id and email address. With that information, the user can join a private team without authorization, effectively gaining access to restricted channels and content.

Affected Systems

Affected versions are Mattermost 11.9.x through 11.9.0, 11.8.x through 11.8.4, 11.7.x through 11.7.7, and 10.11.x through 10.11.22. The issue applies to all installations that expose the /api/v4/data_retention/policies/{policy_id}/teams endpoint and grant read‑only Data Retention Policy rights to users.

Risk and Exploitability

The CVSS score is 6.5, indicating a moderate severity. The EPSS score is unavailable, so the current exploitation probability is unknown. Because the vulnerability requires authentication and specific permissions, the attack surface is limited to users who have been granted read‑only Data Retention Policy rights. The vulnerability is not listed in the CISA KEV catalog, but it still permits unauthorized access to private teams.

Generated by OpenCVE AI on September 15, 2026 at 10:09 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.


OpenCVE Recommended Actions

  • Upgrade Mattermost to the latest patched versions (11.10.0 or newer, 11.9.1 or newer, 11.8.5 or newer, 11.7.8 or newer, or 10.11.23 or newer).
  • If an upgrade is not immediately possible, remove or revoke the read‑only Data Retention Policy permission from user accounts that do not need it to access data retention policies.
  • Consider disabling or restricting access to the /api/v4/data_retention/policies/{policy_id}/teams endpoint until the issue is resolved.

Generated by OpenCVE AI on September 15, 2026 at 10:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 15 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data Retention Policy permission to obtain a private team's secret invite_id and email, and use it to join the team without authorization, via GET /api/v4/data_retention/policies/{policy_id}/teams.. Mattermost Advisory ID: MMSA-2026-00702
Title Data Retention Teams Endpoint Leaks Private Team Invite ID
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-14T21:21:47.436Z

Reserved: 2026-09-14T21:20:45.375Z

Link: CVE-2026-91181

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T22:16:59.643

Modified: 2026-09-14T22:16:59.643

Link: CVE-2026-91181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T10:15:17Z

Weaknesses