Mattermost · Mattermost · CVE-2026-9824
**Name of the Vulnerable Software and Affected Versions**
Mattermost versions 11.7.0 through 11.7.2
Mattermost versions 11.6.0 through 11.6.4
Mattermost versions 10.11.0 through 10.11.19
**Description**
An issue exists where the `/share-channel` autocomplete handler fails to verify the `manage shared channels` permission. This allows an authenticated user who lacks this permission to enumerate metadata related to configured remote cluster connections using slash command autocomplete.
**Recommendations**
Update Mattermost versions 11.7.0 through 11.7.2 to a version newer than 11.7.2.
Update Mattermost versions 11.6.0 through 11.6.4 to a version newer than 11.6.4.
Update Mattermost versions 10.11.0 through 10.11.19 to a version newer than 10.11.19.