PT-2026-57663 · Mattermost · Mattermost

·

CVE-2026-9597

·

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 11.6.x through 11.6.4 Mattermost versions 11.7.x through 11.7.2
Description The software fails to verify the activation status of a guest account during the session creation process in the magic-link token login path. This allows a deactivated guest user to obtain a fully functional session if they possess a magic-link token that was issued before the account was deactivated.
Recommendations Update Mattermost versions 11.6.x to a version newer than 11.6.4. Update Mattermost versions 11.7.x to a version newer than 11.7.2.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9597

Affected Products

Mattermost