PT-2026-91745 · Mattermost · Mattermost

·

CVE-2026-91181

·

Published

2026-09-14

·

Updated

2026-09-16

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mattermost version 11.9.0 Mattermost versions 11.8.x through 11.8.4 Mattermost versions 11.7.x through 11.7.7 Mattermost versions 10.11.x through 10.11.22
Description An issue exists where Team objects returned by the data retention teams endpoint are not properly sanitized. This allows an authenticated user with read-only Data Retention Policy permissions to obtain the secret invite id and email of a private team, enabling unauthorized access to join that team. The issue is triggered via the 'GET /api/v4/data retention/policies/{policy id}/teams' endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict access to the 'GET /api/v4/data retention/policies/{policy id}/teams' endpoint to minimize the risk of exploitation.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91181

Affected Products

Mattermost