CVE-2026-9693
Received Received - Intake

Thread Membership Exposure in Mattermost

Vulnerability report for CVE-2026-9693, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: Mattermost, Inc.

Description

Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads API.. Mattermost Advisory ID: MMSA-2026-00682

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
mattermost mattermost to 10.11.20 (inc)
mattermost mattermost to 11.7.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-459 The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Mattermost versions between 10.11.0 and 10.11.20, and 11.7.0 and 11.7.5, fail to delete thread membership records when a user leaves or is removed from a team. This means a previously removed user who is later re-invited can still access private channel thread content and metadata through the team threads API.

Detection Guidance

This vulnerability involves Mattermost failing to remove thread membership records when a user leaves a team. Detection requires checking Mattermost database records for orphaned thread memberships. Use Mattermost API or database queries to identify users with access to private channel threads despite being removed from the team.

Impact Analysis

If you use Mattermost in these affected versions, a former team member who was removed could regain access to private discussions they were previously part of. This exposes sensitive conversations and metadata to unauthorized users.

Compliance Impact

The vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access to private channel thread content and metadata for previously removed users who are re-invited to a team. This unauthorized access may violate data protection requirements under these regulations.

Mitigation Strategies

Update Mattermost to a version that fixes this issue. Specifically, upgrade to versions beyond 10.11.20 or 11.7.5 to remove thread membership records when users leave teams.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9693. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart