CVE-2026-28759
published 2026-05-18CVE-2026-28759: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing…
PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.15%
4.9th percentile
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious remote cluster to remove any user from any channel, including private channels, via crafted membership sync messages targeting channels the remote cluster is not authorized to access. Mattermost Advisory ID: MMSA-2026-00576
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 5.3.2-0.20260216150504-8738f8c4b3d4 | 5.3.2-0.20260216150504-8738f8c4b3d4 |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20260216150504-8738f8c4b3d4 | 8.0.0-20260216150504-8738f8c4b3d4 |
| github.com | mattermost_mattermost_server_v8 | >= 10.11.0 < 10.11.14 | 10.11.14 |
| github.com | mattermost_mattermost_server_v8 | >= 11.4.0 < 11.4.4 | 11.4.4 |
| github.com | mattermost_mattermost_server_v8 | >= 11.5.0 < 11.5.2 | 11.5.2 |
| mattermost | mattermost | 10.11.0 – 10.11.13 | — |
| mattermost | mattermost | 11.4.0 – 11.4.3 | — |
| mattermost | mattermost | 11.5.0 – 11.5.1 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.14 | 10.11.14 |
| mattermost | mattermost_server | >= 11.4.0 < 11.4.4 | 11.4.4 |
| mattermost | mattermost_server | >= 11.5.0 < 11.5.2 | 11.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mattermost does not verify remote cluster channel access when processing shared channel membership removals
ghsa·2026-05-18
CVE-2026-28759 [MEDIUM] CWE-863 Mattermost does not verify remote cluster channel access when processing shared channel membership removals
Mattermost does not verify remote cluster channel access when processing shared channel membership removals
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious remote cluster to remove any user from any channel, including private channels, via crafted membership sync messages targeting channels the remote cluster is not authorized to access. Mattermost Advisory ID: MMSA-2026-00576.
VulDB
Mattermost up to 10.11.13/11.4.3/11.5.1 Membership authorization
vuldb·2026-05-18·CVSS 4.3
CVE-2026-28759 [MEDIUM] Mattermost up to 10.11.13/11.4.3/11.5.1 Membership authorization
A vulnerability identified as problematic has been detected in Mattermost up to 10.11.13/11.4.3/11.5.1. This affects an unknown part of the component Membership Handler. Performing a manipulation results in incorrect authorization.
This vulnerability was named CVE-2026-28759. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
GHSA
GHSA-8h9w-w78c-vvr3: Mattermost versions 11
ghsa_unreviewed·2026-05-18
CVE-2026-28759 [MEDIUM] CWE-863 GHSA-8h9w-w78c-vvr3: Mattermost versions 11
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious remote cluster to remove any user from any channel, including private channels, via crafted membership sync messages targeting channels the remote cluster is not authorized to access. Mattermost Advisory ID: MMSA-2026-00576
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-18
Published