CVE-2026-9693 - Mattermost thread memberships persist after team removal, exposing private channel thread metadata on re-invite
CVE ID :CVE-2026-9693
Published : Aug. 17, 2026, 11:16 p.m. | 1 hour, 20 minutes ago
Description :Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads API.. Mattermost Advisory ID: MMSA-2026-00682
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 17, 2026, 11:16 p.m. | 1 hour, 20 minutes ago
Description :Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads API.. Mattermost Advisory ID: MMSA-2026-00682
Severity: 3.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...