CyberRota Analysis
AI-GeneratedMattermost versions 11.7.x up to 11.7.6, 10.11.x up to 10.11.21, and 11.8.x up to 11.8.3 are vulnerable due to inadequate validation of user access rights to channels, enabling authenticated attackers to expose the membership of private channels by manipulating board links. This vulnerability could lead to unauthorized disclosure of sensitive team information. Organizations using these versions should prioritize patching to mitigate the risk of information leakage.
Original NVD Description
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that users have read access to a channel before linking a board to it, which allows an authenticated attacker to discover the membership of private channels on the same team via creating, patching, importing, or bulk-creating boards with an arbitrary channelId. Mattermost Advisory ID: MMSA-2026-00674
Related CVEs
Other vulnerabilities affecting the same vendor(s)