Junglewise Threat Intelligence

CVE-2026-3636: Mattermost information disclosure in team API endpoints

CVE-2026-3636 · Severity: medium · CVSS 4.3 · Published 2026-05-22

Technologies: Mattermost Server, github.com/mattermost/mattermost-server (Go). Vendors: Mattermost, Go.

Executive brief

Mattermost, a collaboration and messaging platform, contains a security flaw where team member information is not properly hidden from unauthorized users. An attacker with a standard user account could use the platform's programming interface (API) to view internal details about other team members' roles that they should not be able to see. While this does not allow for full account takeover, it results in the unauthorized disclosure of internal organizational structure and user permissions.

Technical details

An information disclosure vulnerability exists in Mattermost Server due to improper sanitization of team member data returned via API endpoints. The vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). A remote attacker with basic user permissions (PR:L) can invoke various team API endpoints to retrieve data regarding team members' roles that should be restricted to administrators. The issue affects versions 10.11.0 through 10.11.14, 11.4.0 through 11.4.4, 11.5.0 through 11.5.3, and 11.6.0. Patches are available in versions 10.11.15, 11.4.5, 11.5.4, 11.6.1, and 11.7.0.

Affected products

  • Mattermost Mattermost Server 10.11.0 to 10.11.14, 11.4.0 to 11.4.4, 11.5.0 to 11.5.3, 11.6.0

Timeline

  • 2026-05-22: advisory: Initial advisory published by Mattermost
  • 2026-05-22: disclosed: CVE-2026-3636 published to NVD

References

Related threats