User Management Vulnerability in Mattermost by Mattermost
CVE-2026-8074
3.8LOW
What is CVE-2026-8074?
Mattermost versions 11.7.0 and 10.11.17 and earlier contain a vulnerability that fails to enforce bot-specific permission checks on the user active status endpoint. This oversight allows a User Manager with write access for user management, but without Integrations permissions, to deactivate bot accounts by exploiting the PUT /api/v4/users/{id}/active API endpoint. This presents a significant risk for applications utilizing bot accounts for automated tasks.
Affected Version(s)
Mattermost 11.7.0
Mattermost 10.11.0 <= 10.11.17
Mattermost 11.8.0