PT-2026-7984 · Mattermost · Mattermost

Juho Forsén

·

Published

2026-02-13

·

Updated

2026-03-03

·

CVE-2026-20796

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 10.11.0 through 10.11.9
Description Mattermost versions 10.11.0 through 10.11.9 do not properly validate channel membership when retrieving data, potentially allowing a deactivated user to learn team names they should not have access to. This occurs due to a race condition in the /common teams API endpoint.
Recommendations Update to a version later than 10.11.9.

Fix

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

CVE-2026-20796
GHSA-2XF7-HMF6-P64J
GO-2026-4495
SUSE-SU-2026:0757-1

Affected Products

Mattermost