cbcvebase.
CVE-2026-21386
published 2026-03-16

CVE-2026-21386: Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows…

PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.18%
8.3th percentile
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error messages for nonexistent versus private channels. Mattermost Advisory ID: MMSA-2026-00588

Affected

14 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 0 < 5.3.2-0.20260130144323-5bb5261c72fa5.3.2-0.20260130144323-5bb5261c72fa
github.commattermost_mattermost-server>= 10.11.0-rc1 < 10.11.1110.11.11
github.commattermost_mattermost-server>= 10.11.0-rc1+incompatible < 10.11.11+incompatible10.11.11+incompatible
github.commattermost_mattermost-server>= 11.2.0-rc1 < 11.2.311.2.3
github.commattermost_mattermost-server>= 11.2.0-rc1+incompatible < 11.2.3+incompatible11.2.3+incompatible
github.commattermost_mattermost-server>= 11.3.0-rc1 < 11.3.111.3.1
github.commattermost_mattermost-server>= 11.3.0-rc1+incompatible < 11.3.1+incompatible11.3.1+incompatible
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20260130144323-5bb5261c72fa8.0.0-20260130144323-5bb5261c72fa
mattermostmattermost10.11.0 – 10.11.10
mattermostmattermost11.2.0 – 11.2.2
mattermostmattermost11.3.0 – 11.3.0
mattermostmattermost_server>= 10.11.0 < 10.11.1110.11.11
mattermostmattermost_server>= 11.2.0 < 11.2.311.2.3
mattermostmattermost_server>= 11.3.0 < 11.3.111.3.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.