PT-2026-7984 · Mattermost · Mattermost

·

CVE-2026-20796

·

Published

2026-02-13

·

Updated

2026-07-30

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 10.11.0 through 10.11.9
Description Mattermost versions 10.11.0 through 10.11.9 do not properly validate channel membership when retrieving data, potentially allowing a deactivated user to learn team names they should not have access to. This occurs due to a race condition in the /common teams API endpoint.
Recommendations Update to a version later than 10.11.9.

Exploit

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-20796
GHSA-2XF7-HMF6-P64J
GO-2026-4495
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:0757-1

Affected Products

Mattermost