Junglewise Threat Intelligence

CVE-2026-28759: Mattermost incorrect authorization in shared channel membership sync

CVE-2026-28759 · Severity: medium · CVSS 4.3 · Published 2026-05-18

Technologies: github.com/mattermost/mattermost-server/v5 (Go), github.com/mattermost/mattermost-server/v6 (Go), Mattermost Server, github.com/mattermost/mattermost/server/v8 (Go), github.com/mattermost/mattermost-server (Go). Vendors: Go, Mattermost.

Executive brief

Mattermost, a collaboration platform for team communication, contains a vulnerability in its shared channel synchronization feature. A malicious remote cluster can send specially crafted messages to remove users from any channel, including private ones, even if the remote cluster should not have access to those channels. This could lead to unauthorized disruption of team communications and the removal of legitimate users from their workspaces.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Mattermost Server's shared channel membership synchronization logic. The application fails to validate that a remote cluster has the appropriate permissions for a specific channel before processing membership removal requests. An attacker controlling a linked remote cluster can exploit this by sending crafted membership sync messages targeting channels they are not authorized to access. This allows the attacker to remove any user from any channel, including private channels. The issue is addressed in versions 11.5.2, 11.4.4, 10.11.14, and specific backported builds.

Affected products

  • Mattermost Mattermost Server 11.5.0 - 11.5.1, 11.4.0 - 11.4.3, 10.11.0 - 10.11.13, < 8.0.0-20260216150504-8738f8c4b3d4

Timeline

  • 2026-05-18: disclosed: Initial disclosure and NVD publication
  • 2026-05-18: advisory: Mattermost Advisory MMSA-2026-00576 published
  • 2026-06-01: other: GitHub Advisory reviewed and updated

References

Related threats