Description
Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671
Published: 2026-07-13
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Certain older versions of Mattermost fail to sanitize data returned by the scheme teams endpoint. A user with the User Manager role can retrieve private invitation links for teams they are not a member of and then use those links to join or share access to those private teams via the same endpoint. This flaw effectively allows the attacker to gain unauthorized access to confidential team data.

Affected Systems

The vulnerability affects Mattermost deployments running any of the following releases: 11.7.0 through 11.7.2 and 10.11.0 through 10.11.19. These impacted versions only pose a risk if a User Manager role is assigned to logged‑in users, because that role is required to query the vulnerable endpoint.

Risk and Exploitability

The CVSS score of 3.8 identifies the flaw as low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog. Based on the description, it is inferred that the primary attack vector is an insider or a credential‑stealing attacker who can authenticate with a User Manager account; no external unauthenticated exploitation path is described.

Generated by OpenCVE AI on July 31, 2026 at 11:40 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.8.0, 11.7.3, 10.11.20 or higher.


OpenCVE Recommended Actions

  • Upgrade Mattermost to a non‑vulnerable release (≥ 11.8.0, ≥ 11.7.3, ≥ 10.11.20).
  • Restrict assignment of the User Manager role to staff who absolutely require it, thereby limiting the pool of accounts that can abuse this flaw.
  • Enable monitoring or logging of new team membership events that are not initiated through the normal invitation workflow to detect potential misuse.

Generated by OpenCVE AI on July 31, 2026 at 11:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 13 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671
Title Mattermost schemes teams endpoint exposes private team invite IDs
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-07-13T13:09:31.383Z

Reserved: 2026-05-28T11:26:12.173Z

Link: CVE-2026-9820

cve-icon Vulnrichment

Updated: 2026-07-13T13:09:27.579Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:45:13Z

Weaknesses