Description
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads API.. Mattermost Advisory ID: MMSA-2026-00682
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 11.9.0, 10.11.21, 11.7.6 or higher.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Mon, 17 Aug 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Mon, 17 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads API.. Mattermost Advisory ID: MMSA-2026-00682 | |
| Title | Mattermost thread memberships persist after team removal, exposing private channel thread metadata on re-invite | |
| Weaknesses | CWE-459 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-08-17T22:07:12.958Z
Reserved: 2026-05-27T10:58:39.051Z
Link: CVE-2026-9693
No data.
Status : Received
Published: 2026-08-17T23:16:52.940
Modified: 2026-08-17T23:16:52.940
Link: CVE-2026-9693
No data.
OpenCVE Enrichment
Updated: 2026-08-17T23:30:04Z
Weaknesses
-
CWE-459
Incomplete Cleanup