User Management Vulnerability in Mattermost by Mattermost
CVE-2026-8074

3.8LOW

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
22 June 2026

What is CVE-2026-8074?

Mattermost versions 11.7.0 and 10.11.17 and earlier contain a vulnerability that fails to enforce bot-specific permission checks on the user active status endpoint. This oversight allows a User Manager with write access for user management, but without Integrations permissions, to deactivate bot accounts by exploiting the PUT /api/v4/users/{id}/active API endpoint. This presents a significant risk for applications utilizing bot accounts for automated tasks.

Affected Version(s)

Mattermost 11.7.0

Mattermost 10.11.0 <= 10.11.17

Mattermost 11.8.0

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hackit_bharat
.