CyberRota Analysis
AI-GeneratedMattermost versions 10.11.x up to 10.11.20 and 11.7.x up to 11.7.5 are vulnerable due to inadequate removal of thread membership records when users leave or are removed from a team. This flaw allows previously removed users, upon re-invitation, to access private channel thread content and metadata through the team threads API, potentially exposing sensitive information. Organizations using affected Mattermost versions should prioritize patching to mitigate the risk of unauthorized access to confidential discussions.
Original NVD Description
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads API.. Mattermost Advisory ID: MMSA-2026-00682
Related CVEs
Other vulnerabilities affecting the same vendor(s)