CyberRota Analysis
AI-GeneratedCertain versions of Mattermost are vulnerable due to inadequate restrictions on the group_constrained channel flag, allowing unauthorized users to remove all participants from group or direct message conversations through the channel patch API. This flaw poses a risk of conversation disruption and potential data loss, impacting user communication and collaboration. Organizations using the affected Mattermost versions should prioritize patching to mitigate this vulnerability.
Original NVD Description
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel patch API.. Mattermost Advisory ID: MMSA-2026-00688
Related CVEs
Other vulnerabilities affecting the same vendor(s)