Junglewise Threat Intelligence

CVE-2026-8823: Mattermost incorrect authorization in demote-user API

CVE-2026-8823 · Severity: low · CVSS 3.8 · Published 2026-06-22

Technologies: Mattermost Server. Vendors: Mattermost.

Executive brief

Mattermost is a collaboration platform used for team communication and incident response. A vulnerability in the user management system allows administrators with lower privileges to demote automated bot accounts to guest status. This could disrupt automated workflows, integrations, and security monitoring tools that rely on these bot accounts to function correctly.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the demote-user API of Mattermost Server. The application fails to properly validate whether a target account is a bot when an administrator attempts to demote a user to a guest role. This allows a high-privileged user (specifically a lower-level administrator) to target and demote arbitrary bot accounts, effectively degrading their permissions and potentially breaking automated integrations. The attack is reachable over the network without user interaction, though it requires administrative privileges. Patches are available in versions 11.8.0, 11.7.1, and 10.11.18.

Affected products

  • Mattermost Mattermost Server 11.7.x <= 11.7.0, 10.11.x <= 10.11.17

Timeline

  • 2026-06-22: disclosed
  • 2026-06-22: advisory

References

Related threats