CVE-2026-6046
published 2026-06-12CVE-2026-6046: Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot…
PriorityP431medium5.3CVSS 3.1
AVNACHPRLUINSUCHINAN
EPSS
0.19%
8.7th percentile
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot registration belongs to a bot account, which allows an unprivileged attacker to intercept private messages sent by plugins via direct message channels by pre-registering a user account with a predictable plugin bot username.. Mattermost Advisory ID: MMSA-2026-00649
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 10.11.0 < 10.11.17 | 10.11.17 |
| github.com | mattermost_mattermost-server | >= 11.5.0 < 11.5.5 | 11.5.5 |
| github.com | mattermost_mattermost-server | >= 11.6.0 < 11.6.1 | 11.6.1 |
| github.com | mattermost_mattermost_server_v8 | >= 8.0.0-20250731163400-5b955468ea1e < 8.0.0-20260428151657-c79c3831061a | 8.0.0-20260428151657-c79c3831061a |
| mattermost | mattermost | 10.11.0 – 10.11.15 | — |
| mattermost | mattermost | 11.5.0 – 11.5.4 | — |
| mattermost | mattermost | 11.6.0 – 11.6.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
ghsa·2026-06-12
CVE-2026-6046 [MEDIUM] CWE-200 Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot registration belongs to a bot account, which allows an unprivileged attacker to intercept private messages sent by plugins via direct message channels by pre-registering a user account with a predictable plugin bot username. Mattermost Advisory ID: MMSA-2026-00649
GHSA
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot registration belongs to a bot account, which allow
ghsa_unreviewed·2026-06-12
CVE-2026-6046 [MEDIUM] CWE-200 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot registration belongs to a bot account, which allow
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot registration belongs to a bot account, which allows an unprivileged attacker to intercept private messages sent by plugins via direct message channels by pre-registering a user account with a predictable plugin bot username.. Mattermost Advisory ID: MMSA-2026-00649
VulDB
Mattermost up to 11.6.x Direct Message information disclosure (EUVD-2026-36502)
vuldb·2026-06-12·CVSS 5.3
CVE-2026-6046 [MEDIUM] Mattermost up to 11.6.x Direct Message information disclosure (EUVD-2026-36502)
A vulnerability categorized as problematic has been discovered in Mattermost up to 10.11.15/10.11.16/11.5.4/11.6.1/11.6.x. This affects an unknown part of the component Direct Message Handler. Such manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-6046. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-12
Published