CyberRota Analysis
AI-GeneratedCertain versions of Mattermost are vulnerable due to inadequate sanitization of team objects returned by the teams API endpoint, allowing users with the User Manager role to generate invite links for private teams. This could lead to unauthorized access and sharing of private team information. Organizations using these versions should prioritize patching to mitigate potential exposure of sensitive team data.
Original NVD Description
Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671
Related CVEs
Other vulnerabilities affecting the same vendor(s)