cbcvebase.
CVE-2026-28759
published 2026-05-18

CVE-2026-28759: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing…

PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.15%
4.9th percentile
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious remote cluster to remove any user from any channel, including private channels, via crafted membership sync messages targeting channels the remote cluster is not authorized to access. Mattermost Advisory ID: MMSA-2026-00576

Affected

11 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 0 < 5.3.2-0.20260216150504-8738f8c4b3d45.3.2-0.20260216150504-8738f8c4b3d4
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20260216150504-8738f8c4b3d48.0.0-20260216150504-8738f8c4b3d4
github.commattermost_mattermost_server_v8>= 10.11.0 < 10.11.1410.11.14
github.commattermost_mattermost_server_v8>= 11.4.0 < 11.4.411.4.4
github.commattermost_mattermost_server_v8>= 11.5.0 < 11.5.211.5.2
mattermostmattermost10.11.0 – 10.11.13
mattermostmattermost11.4.0 – 11.4.3
mattermostmattermost11.5.0 – 11.5.1
mattermostmattermost_server>= 10.11.0 < 10.11.1410.11.14
mattermostmattermost_server>= 11.4.0 < 11.4.411.4.4
mattermostmattermost_server>= 11.5.0 < 11.5.211.5.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.