
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-9693 is a data disclosure vulnerability in Mattermost Server caused by incomplete cleanup of thread membership records when users are removed from or leave a team. Affected versions include Mattermost Server 10.11.0–10.11.20 and 11.7.0–11.7.5. When a previously removed user is later re-invited to the team, stale thread membership records allow them to view private channel thread root post content and metadata via the team threads API. It was published on August 17, 2026, with patches released shortly after. The vulnerability carries a CVSS v3.1 base score of 3.5 (Low) (GitHub Advisory, Mattermost Security).
The root cause is classified as CWE-459 (Incomplete Cleanup): Mattermost fails to purge thread membership records from its database when a user is removed from or voluntarily leaves a team. These orphaned records persist and are not invalidated upon re-invitation, meaning the re-invited user inherits their prior thread membership state. Exploitation requires the attacker to be an authenticated, low-privileged user who was previously a team member, was removed, and was subsequently re-invited — at which point they can query the team threads API to retrieve private channel thread root post content and metadata they should no longer have access to. No public proof-of-concept exploit code has been identified (GitHub Advisory, Mattermost Security).
Successful exploitation results in unauthorized disclosure of private channel thread root post content and associated metadata to a re-invited user who should not have access to those threads. The impact is limited to confidentiality (low), with no integrity or availability consequences. The scope is constrained to the affected Mattermost instance, and lateral movement potential is minimal; however, exposure of private channel content could reveal sensitive organizational communications (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept for CVE-2026-9693. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable and requires user interaction (re-invitation to the team), limiting its practical exploitability. The EPSS score is approximately 0.156%, indicating a low probability of exploitation in the near term (GitHub Advisory, Mattermost Security).
GET /api/v4/users/{user_id}/teams/{team_id}/threads) using their valid session token./api/v4/users/{user_id}/teams/{team_id}/threads from users who were recently re-added to a team, particularly if those users are not current members of the private channels whose thread content is returned.ThreadMembership records in the Mattermost database for users who are no longer active members of the associated private channels.Mattermost has released patched versions addressing this vulnerability: upgrade to 10.11.21 or later for the 10.11.x branch, and 11.7.6 or later (or 11.9.0+) for the 11.7.x branch. As a workaround, administrators should audit team membership changes — particularly for users who have been removed and re-invited — and verify they only have access to appropriate channels. Restricting thread API access to users with current valid channel membership is also recommended where feasible (Mattermost Security, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."