SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-9597

MEDIUM · CVSS 5.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

Certain versions of Mattermost are vulnerable due to improper verification of guest account status during the magic-link token login process, allowing deactivated guest users to access active sessions. This could lead to unauthorized access and potential data exposure. Organizations using affected Mattermost versions should prioritize patching to mitigate the risk of unauthorized user access.

CVE
CVE-2026-9597
Severity
MEDIUM
CVSS
5.4
EPSS
0.14%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681

Related CVEs

Other vulnerabilities affecting the same vendor(s)