Executive brief
Mattermost is a popular team communication and collaboration platform. When an administrator revokes a user's session globally (e.g., after detecting a compromise or terminating employment), users with active WebSocket connections may remain authenticated and continue accessing real-time messages and events until their cached credentials expire or they manually reconnect. This means a compromised or terminated user account can persist in receiving sensitive team communications for an extended period despite being revoked.
Technical details
This vulnerability is a session management flaw (CWE-613: Insufficient Session Expiration) in Mattermost's WebSocket authentication layer. When a global session revocation is triggered, the server fails to invalidate cached authentication tokens for clients maintaining persistent WebSocket connections. An attacker with an existing WebSocket connection to the Mattermost server can exploit this by maintaining that connection after their session is revoked; the server will continue to authenticate requests and deliver real-time events until either the local cache expires or the client reconnects and re-authenticates. The vulnerability requires the attacker to have had legitimate access initially (privilege level: low) and a network connection to the Mattermost server (attack vector: network). Patches are available in versions 11.7.1, 11.6.3, 11.5.6, and 10.11.18.
Affected products
- Mattermost Mattermost Server 11.7.0, 11.6.0-11.6.2, 11.5.0-11.5.5, 10.11.0-10.11.17
Timeline
- 2026-06-22: disclosed: Published to GitHub Advisory Database
- 2026-06-22: patched: Patches released: 11.7.1, 11.6.3, 11.5.6, 10.11.18
- 2026-06-22: advisory: Mattermost Advisory ID: MMSA-2026-00664