CVE-2026-9820
⚪ Do wiadomości
Brak sanitizacji obiektów zespołów w Mattermost pozwala na nieautoryzowane dołączenie do prywatnych zespołów.
CVSS
3.8
EPSS
0.0%
Exploit
none
Vendor
mattermost
Opis źródłowy (NVD)
Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 3.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.0% |
| Opublikowano (NVD) | 2026-07-13 11:16:28 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-13 20:38:36 UTC |
Referencje
- https://mattermost.com/security-updates (responsibledisclosure@mattermost.com) [Vendor Advisory]