Junglewise Threat Intelligence

CVE-2026-9597: Mattermost authentication bypass for deactivated guest accounts via magic-link

CVE-2026-9597 · Severity: medium · CVSS 5.4 · Published 2026-07-13

Technologies: Mattermost Server. Vendors: Mattermost.

Executive brief

Mattermost, a popular enterprise collaboration and messaging platform, contains a flaw where deactivated guest accounts can still access the system. If a guest user was previously issued a 'magic-link' login token, they can use that token to bypass their account deactivation and start a fully functional session. This could allow former contractors or external partners to maintain unauthorized access to internal communications after their access should have been revoked.

Technical details

An authentication bypass vulnerability (CWE-305) exists in the magic-link token login path of Mattermost Server. The application fails to perform a status check to verify if a guest account is deactivated before establishing a new session via a magic-link. An attacker who is a deactivated guest user can gain a fully functional session if they possess a magic-link token issued prior to their deactivation. This requires the attacker to have network reachability to the Mattermost instance and a valid, unexpired token. The issue is resolved in versions 11.8.0, 11.7.3, and 11.6.5.

Affected products

  • Mattermost Mattermost Server 11.7.0 - 11.7.2, 11.6.0 - 11.6.4

Timeline

  • 2026-07-13: advisory: Mattermost advisory MMSA-2026-00681 published
  • 2026-07-13: disclosed: CVE-2026-9597 published to NVD

References

Related threats