Description
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster connection metadata via slash command autocomplete.. Mattermost Advisory ID: MMSA-2026-00676
Published: 2026-07-13
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost fails to enforce the manage_shared_channels permission when processing the /share-channel autocomplete handler, exposing an authorization weakness per CWE-862. This flaw allows an authenticated user without that permission to request and enumerate metadata about remote cluster connections through slash command autocomplete, resulting in the disclosure of cluster configuration details.

Affected Systems

Affected vendors and products include Mattermost. Specifically, Mattermost server versions 10.11.x up to 10.11.19, 11.6.x up to 11.6.4, and 11.7.x up to 11.7.2 are vulnerable.

Risk and Exploitability

The CVSS base score of 4.3 indicates a moderate risk for information disclosure. Because the vulnerability requires an authenticated user, it is not a remote code execution flaw but permits unauthorized disclosure of cluster metadata via normal slash command autocomplete usage. The EPSS score of <1% signals a low exploitation probability, and the issue is not listed in CISA’s KEV catalog, implying limited public exploitation. The likely attack vector is routine use of the slash command autocomplete feature by an authenticated user lacking the manage_shared_channels permission.

Generated by OpenCVE AI on July 31, 2026 at 11:40 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.8.0, 11.7.3, 11.6.5, 10.11.20 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to version 11.8.0, 11.7.3, 11.6.5, 10.11.20 or later to apply the vendor patch that enforces permission checks on the /share-channel autocomplete handler.
  • Restrict or revoke the manage_shared_channels permission for all non-privileged users to reduce potential enumeration opportunities.
  • Disable the slash command autocomplete feature in the Mattermost configuration until the patch can be applied.

Generated by OpenCVE AI on July 31, 2026 at 11:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster connection metadata via slash command autocomplete.. Mattermost Advisory ID: MMSA-2026-00676
Title Remote cluster metadata enumeration via /share-channel autocomplete
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-07-13T13:10:35.463Z

Reserved: 2026-05-28T11:32:33.594Z

Link: CVE-2026-9824

cve-icon Vulnrichment

Updated: 2026-07-13T13:10:32.896Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:45:13Z

Weaknesses