Junglewise Threat Intelligence

CVE-2026-9820: Mattermost information disclosure in scheme teams API endpoint

CVE-2026-9820 · Severity: low · CVSS 3.8 · Published 2026-07-13

Technologies: Mattermost Server. Vendors: Mattermost.

Executive brief

Mattermost, a collaboration and messaging platform, contains a security flaw where internal team information is not properly hidden from certain administrative users. An authorized user with the 'User Manager' role can view invite links for private teams they are not supposed to access. This could allow them to join restricted teams or share access with others, potentially exposing sensitive internal discussions.

Technical details

A missing authorization and improper sanitization vulnerability (CWE-862) exists in the Mattermost scheme teams API endpoint. The endpoint returns team objects that include sensitive metadata, such as invite links, which are not filtered based on the requester's permissions. An attacker with the 'User Manager' role can exploit this to discover invite links for private teams they do not belong to, enabling unauthorized joining or sharing of those teams. The issue is resolved in versions 11.7.3, 10.11.20, and 11.8.0.

Affected products

  • Mattermost Mattermost Server 11.7.0 - 11.7.2, 10.11.0 - 10.11.19

Timeline

  • 2026-07-13: advisory
  • 2026-07-13: disclosed

References

Related threats