Inadequate Thread Membership Management in Mattermost by Mattermost Inc.
CVE-2026-9693
3.5LOW
What is CVE-2026-9693?
The Mattermost platform has a vulnerability that arises when a user leaves or is removed from a team. It fails to clean up thread membership records, enabling these users to regain access to private channel content and metadata through the team threads API if they are later re-invited. This oversight can lead to unauthorized visibility of sensitive information, thereby compromising the security posture of teams using the platform.
Affected Version(s)
Mattermost 10.11.0 <= 10.11.20
Mattermost 11.7.0 <= 11.7.5
Mattermost 11.9.0