Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data Retention Policy permission to obtain a private team's secret invite_id and email, and use it to join the team without authorization, via GET /api/v4/data_retention/policies/{policy_id}/teams.. Mattermost Advisory ID: MMSA-2026-00702
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Private Team via Exposed Invite ID
Action: Patch
AI Analysis

Impact

Mattermost versions before 11.9.1, 11.8.5, 11.7.8 and 10.11.23 fail to sanitize team objects returned from the data‑retention policies endpoint. An authenticated user who only holds the read‑only Data Retention Policy permission can read the secret invite_id and email address of a private team. With that information the user can construct a join request and become a member of the private team without authorization, thereby gaining access to restricted channels and conversations.

Affected Systems

Mattermost installations using version 10.11.0 through 10.11.22, 11.7.0 through 11.7.7, 11.8.0 through 11.8.4, and 11.9.0 or earlier are affected. All deployments that expose the /api/v4/data_retention/policies/{policy_id}/teams endpoint and grant users read‑only Data Retention Policy rights are vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability that the specific conditions required for exploitation—namely an authenticated user with the correct minimal permission—are met. The vulnerability is not listed in CISA’s KEV catalog. If an attacker can meet the prerequisite permissions, they can retrieve the private team’s invite_id and use it to join the team, effectively bypassing team membership controls.

Generated by OpenCVE AI on September 17, 2026 at 19:47 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to the patched releases (11.10.0 or newer, 11.9.1 or newer, 11.8.5 or newer, 11.7.8 or newer, or 10.11.23 or newer).
  • Restrict or remove the read‑only Data Retention Policy permission from users who do not require it to limit the ability to discover private team invite IDs.
  • Disable or limit access to the /api/v4/data_retention/policies/{policy_id}/teams endpoint until the vulnerability is fixed.

Generated by OpenCVE AI on September 17, 2026 at 19:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data Retention Policy permission to obtain a private team's secret invite_id and email, and use it to join the team without authorization, via GET /api/v4/data_retention/policies/{policy_id}/teams.. Mattermost Advisory ID: MMSA-2026-00702
Title Data Retention Teams Endpoint Leaks Private Team Invite ID
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-16T03:56:15.095Z

Reserved: 2026-09-14T21:20:45.375Z

Link: CVE-2026-91181

cve-icon Vulnrichment

Updated: 2026-09-15T19:15:37.277Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T22:16:59.643

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-91181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses