Description
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads API.. Mattermost Advisory ID: MMSA-2026-00682
Published: 2026-08-17
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost versions earlier than 10.11.21 and 11.7.6 allow a user who has been removed or left a team to retain thread membership records. When that user is re‑invited, the API inadvertently exposes private channel thread root post content and metadata, resulting in a confidentiality breach of private thread data. The flaw arises from a failure to properly delete thread membership records during team removal, identified as CWE‑459.

Affected Systems

Mattermost is affected in releases 10.11.0 through 10.11.20 and 11.7.0 through 11.7.5. The vendor recommends updating to 10.11.21, 11.7.6, 11.9.0 or any subsequent release to remediate the issue.

Risk and Exploitability

The CVSS score is 3.5, indicating low severity. No EPSS data is available and the vulnerability is not listed in CISA KEV. Exploitation requires the attacker to be a user who was previously removed from a team, subsequently re‑invited, and then query the team threads API. The risk is confined to users with prior access and does not allow remote code execution or a full system compromise.

Generated by OpenCVE AI on August 18, 2026 at 00:46 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.9.0, 10.11.21, 11.7.6 or higher.


OpenCVE Recommended Actions

  • Upgrade Mattermost to the latest supported version (10.11.21, 11.7.6, 11.9.0, or newer).
  • As an interim measure, use the Mattermost admin console or a suitable script to manually delete the lingering thread membership records for users who have been removed or re‑invited.
  • If immediate patching is not feasible, recreate the affected team or force a fresh team join for each user to invalidate any remaining thread memberships and prevent further exposure.

Generated by OpenCVE AI on August 18, 2026 at 00:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 17 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads API.. Mattermost Advisory ID: MMSA-2026-00682
Title Mattermost thread memberships persist after team removal, exposing private channel thread metadata on re-invite
Weaknesses CWE-459
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Mattermost Mattermost Mattermost Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-08-18T14:21:04.540Z

Reserved: 2026-05-27T10:58:39.051Z

Link: CVE-2026-9693

cve-icon Vulnrichment

Updated: 2026-08-18T14:20:59.195Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-17T23:16:52.940

Modified: 2026-08-19T13:14:34.433

Link: CVE-2026-9693

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T01:00:05Z

Weaknesses