Executive brief
Mattermost is a team collaboration platform that supports connecting to remote clusters for distributed deployments. A flaw in how the product handles authentication token responses during remote cluster configuration updates allows certain privileged users to extract sensitive cluster credentials. An attacker with the appropriate administrative permission could intercept or retrieve remote cluster authentication tokens, potentially gaining unauthorized access to connected infrastructure and compromising the security of distributed Mattermost installations.
Technical details
This vulnerability is an information disclosure issue (CWE-201) caused by insufficient output sanitization in the Remote Cluster API PATCH endpoint. The vulnerability affects the handling of authentication token fields (Token and RemoteToken) in the API response; these sensitive credentials are returned unsanitized to authenticated callers. Exploitation requires network access to the Mattermost API and valid authentication with the manage_secure_connections permission. An attacker with this permission can issue a PATCH request to the remote cluster endpoint and extract the authentication tokens from the response, allowing them to impersonate the remote cluster connection. Patches are available in versions 11.6.2 (or 11.6.1), 11.5.5, 10.11.16, and later releases. The fix involves sanitizing the Token and RemoteToken fields before returning the response to the client.
Affected products
- Mattermost Mattermost Server 11.6.0 to 11.6.1, 11.5.0 to 11.5.4, 10.11.0 to 10.11.15
- Mattermost mattermost-server (Go module) 8.0.0-20250731163400-5b955468ea1e to before 8.0.0-20260428142921-bd8fc9222672
Timeline
- 2026-06-12: disclosed: Vulnerability disclosed in GitHub Advisory GHSA-9p44-r552-4wp9
- 2026-04-28: patched: Fix merged in PR #36288 (master branch); cherry-picked to release branches 11.7, 11.6, 11.5, and 10.11
- 2026-06-12: other: CVE-2026-7184 assigned