Vulnerability GHSA-xmfh-3ccg-c9fx
Low Risk
LOW RISK
CVSS Score: 3.8
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
3 months ago
June 22, 2026 at 06:34 PM UTC
Mattermost has an Incorrect Authorization issue
v10.11.0+incompatible - v10.11.17+incompatible and v11.7.0+incompatible
v10.11.0+incompatible - v10.11.17+incompatible and v11.7.0+incompatible
Summary
Mattermost has an Incorrect Authorization issue
Details
Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard demote-user API.. Mattermost Advisory ID: MMSA-2026-00669
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
6 hours ago
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server
>=10.11.0+incompatible <10.11.18+incompatible GO-2026-6547
>=10.11.0+incompatible <10.11.18+incompatible GO-2026-6547
Unknown
6 hours ago
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server
<8.0.0-20260518160100-9bd77d3fc4d2 GO-2026-6547
<8.0.0-20260518160100-9bd77d3fc4d2 GO-2026-6547
Unknown
3 days ago
Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler in github.com/mattermost/mattermost-server
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6480
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6480
Unknown
3 days ago
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint in github.com/mattermost/mattermost-server
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6481
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6481
Unknown
3 days ago
Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation in github.com/mattermost/mattermost-server
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6482
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6482
Impacted packages
Timeline
Published
3 months ago
June 22, 2026 at 06:34 PM UTC
Last Modified
6 hours ago
October 01, 2026 at 08:56 PM UTC