SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-10085

MEDIUM · CVSS 5.4 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

Certain versions of Mattermost are vulnerable due to inadequate restrictions on the group_constrained channel flag, allowing unauthorized users to remove all participants from group or direct message conversations through the channel patch API. This flaw poses a risk of conversation disruption and potential data loss, impacting user communication and collaboration. Organizations using the affected Mattermost versions should prioritize patching to mitigate this vulnerability.

CVE
CVE-2026-10085
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel patch API.. Mattermost Advisory ID: MMSA-2026-00688

Related CVEs

Other vulnerabilities affecting the same vendor(s)