Vulnerability GHSA-xmfh-3ccg-c9fx

Low Risk
LOW RISK
CVSS Score: 3.8
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
3 months ago
June 22, 2026 at 06:34 PM UTC
Mattermost has an Incorrect Authorization issue
v10.11.0+incompatible - v10.11.17+incompatible and v11.7.0+incompatible
v10.11.0+incompatible - v10.11.17+incompatible and v11.7.0+incompatible

Summary

Mattermost has an Incorrect Authorization issue

Details

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard demote-user API.. Mattermost Advisory ID: MMSA-2026-00669

Timeline

Published
3 months ago
June 22, 2026 at 06:34 PM UTC
Last Modified
6 hours ago
October 01, 2026 at 08:56 PM UTC