User Demotion Vulnerability in Mattermost by Mattermost
CVE-2026-8823
3.8LOW
What is CVE-2026-8823?
The Mattermost platform, specifically versions 11.7.x up to 11.7.0 and 10.11.x up to 10.11.17, contains a significant flaw in its user demotion functionality. When demoting users to guest status, the system fails to properly validate bot targets. This oversight allows a lower-privileged administrator to alter or degrade arbitrary bot accounts using the standard demote-user API. Such actions can result in potential disruptions and unauthorized access to bot functionalities, posing security risks for organizations utilizing Mattermost.
Affected Version(s)
Mattermost 11.7.0
Mattermost 10.11.0 <= 10.11.17
Mattermost 11.8.0