SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-9824

MEDIUM · CVSS 4.3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

Certain versions of Mattermost are vulnerable due to improper permission checks in the /share-channel autocomplete handler, allowing authenticated users without the necessary manage_shared_channels permission to access sensitive remote cluster connection metadata. This could lead to unauthorized information disclosure, potentially exposing critical configuration details. Organizations using affected Mattermost versions should prioritize applying the relevant updates to mitigate this risk.

CVE
CVE-2026-9824
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster connection metadata via slash command autocomplete.. Mattermost Advisory ID: MMSA-2026-00676

Related CVEs

Other vulnerabilities affecting the same vendor(s)