Impact
Mattermost versions earlier than 10.11.21 and 11.7.6 allow a user who has been removed or left a team to retain thread membership records. When that user is re‑invited, the API inadvertently exposes private channel thread root post content and metadata, resulting in a confidentiality breach of private thread data. The flaw arises from a failure to properly delete thread membership records during team removal, identified as CWE‑459.
Affected Systems
Mattermost is affected in releases 10.11.0 through 10.11.20 and 11.7.0 through 11.7.5. The vendor recommends updating to 10.11.21, 11.7.6, 11.9.0 or any subsequent release to remediate the issue.
Risk and Exploitability
The CVSS score is 3.5, indicating low severity. No EPSS data is available and the vulnerability is not listed in CISA KEV. Exploitation requires the attacker to be a user who was previously removed from a team, subsequently re‑invited, and then query the team threads API. The risk is confined to users with prior access and does not allow remote code execution or a full system compromise.
OpenCVE Enrichment