SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-9820

LOW · CVSS 3.8 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

Certain versions of Mattermost are vulnerable due to inadequate sanitization of team objects returned by the teams API endpoint, allowing users with the User Manager role to generate invite links for private teams. This could lead to unauthorized access and sharing of private team information. Organizations using these versions should prioritize patching to mitigate potential exposure of sensitive team data.

CVE
CVE-2026-9820
Severity
LOW
CVSS
3.8
EPSS
0.15%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671

Related CVEs

Other vulnerabilities affecting the same vendor(s)