Data Exposure Vulnerability in Mattermost for Team Object Management
CVE-2026-91181

6.5MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
14 September 2026

What is CVE-2026-91181?

Mattermost versions up to 11.9.0, 11.8.4, 11.7.7, and 10.11.22 are susceptible to a data exposure vulnerability due to inadequate sanitization of Team objects retrieved from the data retention teams endpoint. This flaw permits an authenticated user with only read access to the Data Retention Policy to capture private team's secret invite_id and email, subsequently allowing unauthorized team membership through API access. Organizations should review application settings and apply necessary patches as detailed in the Mattermost advisory MMSA-2026-00702 to mitigate this risk.

Affected Version(s)

Mattermost 11.9.0

Mattermost 11.8.0 <= 11.8.4

Mattermost 11.7.0 <= 11.7.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0x7oda7123
.