AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-9693

LOW · CVSS 3.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

Mattermost versions 10.11.x up to 10.11.20 and 11.7.x up to 11.7.5 are vulnerable due to inadequate removal of thread membership records when users leave or are removed from a team. This flaw allows previously removed users, upon re-invitation, to access private channel thread content and metadata through the team threads API, potentially exposing sensitive information. Organizations using affected Mattermost versions should prioritize patching to mitigate the risk of unauthorized access to confidential discussions.

CVE
CVE-2026-9693
Severity
LOW
CVSS
3.5
EPSS
0.16%

Original NVD Description

Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads API.. Mattermost Advisory ID: MMSA-2026-00682

Related CVEs

Other vulnerabilities affecting the same vendor(s)