CyberRota Analysis
AI-GeneratedCertain versions of Mattermost are vulnerable due to improper verification of guest account status during the magic-link token login process, allowing deactivated guest users to access active sessions. This could lead to unauthorized access and potential data exposure. Organizations using affected Mattermost versions should prioritize patching to mitigate the risk of unauthorized user access.
Original NVD Description
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681
Related CVEs
Other vulnerabilities affecting the same vendor(s)