PT-2026-41640 · Mattermost · Mattermost

Daw10

·

Published

2026-05-18

·

Updated

2026-05-18

·

CVE-2026-28759

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 11.5.0 through 11.5.1 Mattermost versions 10.11.0 through 10.11.13 Mattermost versions 11.4.0 through 11.4.3
Description An issue exists during shared channel membership sync where the system fails to validate if a remote cluster has access to a channel before processing membership removal requests. This allows a malicious remote cluster to remove any user from any channel, including private channels, by sending crafted membership sync messages targeting channels the remote cluster is not authorized to access.
Recommendations Update Mattermost versions 11.5.0 through 11.5.1 to a version newer than 11.5.1. Update Mattermost versions 10.11.0 through 10.11.13 to a version newer than 10.11.13. Update Mattermost versions 11.4.0 through 11.4.3 to a version newer than 11.4.3.

Fix

DoS

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28759
GHSA-8H9W-W78C-VVR3

Affected Products

Mattermost