User Demotion Vulnerability in Mattermost by Mattermost
CVE-2026-8823

3.8LOW

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
22 June 2026

What is CVE-2026-8823?

The Mattermost platform, specifically versions 11.7.x up to 11.7.0 and 10.11.x up to 10.11.17, contains a significant flaw in its user demotion functionality. When demoting users to guest status, the system fails to properly validate bot targets. This oversight allows a lower-privileged administrator to alter or degrade arbitrary bot accounts using the standard demote-user API. Such actions can result in potential disruptions and unauthorized access to bot functionalities, posing security risks for organizations utilizing Mattermost.

Affected Version(s)

Mattermost 11.7.0

Mattermost 10.11.0 <= 10.11.17

Mattermost 11.8.0

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Edgar Bellot MicĂł
.