
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20796 is a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in Mattermost Server that allows a deactivated user to discover team names they should not have access to. It affects Mattermost Server versions 10.11.0 through 10.11.9, with version 10.11.10 containing the fix. The vulnerability was published on February 13, 2026, under Mattermost Advisory ID MMSA-2025-00549. It carries a CVSS v3.1 base score of 3.1 (Low severity) (GitHub Advisory, Mattermost Security).
The root cause is classified as CWE-367 (Time-of-Check Time-of-Use Race Condition): Mattermost fails to properly validate channel membership at the time of data retrieval, creating a window between the membership check and the actual data access. An attacker exploiting this flaw must be a deactivated user with network access and low privileges, and must time their request to the /common_teams API endpoint during the race condition window. The high attack complexity reflects the timing requirement inherent in exploiting TOCTOU flaws. No public proof-of-concept code has been identified (GitHub Advisory).
Successful exploitation results in a limited confidentiality breach: a deactivated user can learn the names of teams they should no longer have access to. There is no impact on data integrity or system availability, and the scope of the vulnerability is unchanged (confined to the Mattermost application). The practical risk is low, as only team name metadata is exposed rather than message content or credentials, and exploitation requires precise timing (GitHub Advisory).
Mattermost has released version 10.11.10 as the patched release addressing this vulnerability. Organizations running Mattermost Server 10.11.0 through 10.11.9 should upgrade to 10.11.10 or later. As an additional measure, administrators should monitor API activity from deactivated user accounts for anomalous requests to the /common_teams endpoint (GitHub Advisory, Mattermost Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."