CVE-2026-10085

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel patch API.. Mattermost Advisory ID: MMSA-2026-00688
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

14 Jul 2026, 13:19

Type Values Removed Values Added
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
First Time Mattermost mattermost Server
Mattermost

13 Jul 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-13 09:16

Updated : 2026-07-14 13:19


NVD link : CVE-2026-10085

Mitre link : CVE-2026-10085

CVE.ORG link : CVE-2026-10085


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-862

Missing Authorization