CyberRota Analysis
AI-GeneratedCertain versions of Mattermost are vulnerable due to improper permission checks in the /share-channel autocomplete handler, allowing authenticated users without the necessary manage_shared_channels permission to access sensitive remote cluster connection metadata. This could lead to unauthorized information disclosure, potentially exposing critical configuration details. Organizations using affected Mattermost versions should prioritize applying the relevant updates to mitigate this risk.
Original NVD Description
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster connection metadata via slash command autocomplete.. Mattermost Advisory ID: MMSA-2026-00676
Related CVEs
Other vulnerabilities affecting the same vendor(s)