Executive brief
Mattermost, a collaboration and messaging platform, contains a security flaw where it fails to properly restrict access to certain administrative information. An authorized user on the platform can view technical details about how the server connects to other remote clusters, even if they do not have the required permissions. This could allow an internal user to gather information about the organization's infrastructure that they should not be able to see.
Technical details
A missing authorization check (CWE-862) exists in the '/share-channel' slash command autocomplete handler. The application fails to verify the 'manage_shared_channels' permission before returning data. An authenticated attacker can exploit this by triggering the autocomplete function to enumerate metadata regarding configured remote cluster connections. The vulnerability is addressed in versions 11.8.0, 11.7.3, 11.6.5, and 10.11.20.
Affected products
- Mattermost Mattermost Server 11.7.0 - 11.7.2, 11.6.0 - 11.6.4, 10.11.0 - 10.11.19
Timeline
- 2026-07-13: disclosed: Initial publication of the advisory
- 2026-07-13: advisory: Mattermost Advisory MMSA-2026-00676 published