Data Exposure Vulnerability in Mattermost for Team Object Management
CVE-2026-91181
6.5MEDIUM
What is CVE-2026-91181?
Mattermost versions up to 11.9.0, 11.8.4, 11.7.7, and 10.11.22 are susceptible to a data exposure vulnerability due to inadequate sanitization of Team objects retrieved from the data retention teams endpoint. This flaw permits an authenticated user with only read access to the Data Retention Policy to capture private team's secret invite_id and email, subsequently allowing unauthorized team membership through API access. Organizations should review application settings and apply necessary patches as detailed in the Mattermost advisory MMSA-2026-00702 to mitigate this risk.
Affected Version(s)
Mattermost 11.9.0
Mattermost 11.8.0 <= 11.8.4
Mattermost 11.7.0 <= 11.7.7