Executive brief
Mattermost, a collaboration and messaging platform, contains a vulnerability that allows regular users to disrupt group conversations. An authorized user in a group or direct message can exploit a flaw in how the system handles group synchronization settings to remove all other participants from the chat. This can lead to a loss of communication history and operational disruption for teams relying on the platform for coordination.
Technical details
A missing authorization vulnerability (CWE-862) exists in Mattermost Server where the 'group_constrained' channel flag is not properly restricted to public and private channels that support group synchronization. By interacting with the channel patch API, an authenticated but otherwise ordinary member of a group or direct message (DM) can apply this flag to conversations where it is not intended. This action results in the removal of all participants from the conversation. The vulnerability is reachable over the network by any authenticated user. Patches are available in versions 11.8.0, 11.7.3, 11.6.5, and 10.11.20.
Affected products
- Mattermost Mattermost Server 11.7.0 - 11.7.2, 11.6.0 - 11.6.4, 10.11.0 - 10.11.19
Timeline
- 2026-07-13: disclosed
- 2026-07-13: advisory