CVE-2026-7184
published 2026-06-12CVE-2026-7184: Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows…
PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.26%
17.1th percentile
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated users with the {{manage_secure_connections}} permission to obtain remote cluster authentication tokens via a PATCH request to the remote cluster endpoint.. Mattermost Advisory ID: MMSA-2026-00662
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 10.11.0 < 10.11.16 | 10.11.16 |
| github.com | mattermost_mattermost-server | >= 11.5.0 < 11.5.5 | 11.5.5 |
| github.com | mattermost_mattermost-server | >= 11.6.0 < 11.6.1 | 11.6.1 |
| github.com | mattermost_mattermost_server_v8 | >= 8.0.0-20250731163400-5b955468ea1e < 8.0.0-20260428142921-bd8fc9222672 | 8.0.0-20260428142921-bd8fc9222672 |
| mattermost | mattermost | 10.11.0 – 10.11.15 | — |
| mattermost | mattermost | 11.5.0 – 11.5.4 | — |
| mattermost | mattermost | 11.6.0 – 11.6.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated users with the
ghsa_unreviewed·2026-06-12
CVE-2026-7184 [MEDIUM] CWE-201 Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated users with the
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated users with the {{manage_secure_connections}} permission to obtain remote cluster authentication tokens via a PATCH request to the remote cluster endpoint.. Mattermost Advisory ID: MMSA-2026-00662
GHSA
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
ghsa·2026-06-12
CVE-2026-7184 [MEDIUM] CWE-201 Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated users with the {{manage_secure_connections}} permission to obtain remote cluster authentication tokens via a PATCH request to the remote cluster endpoint. Mattermost Advisory ID: MMSA-2026-00662
VulDB
Mattermost up to 11.6.x Remote Cluster API insertion of sensitive information into sent data (EUVD-2026-36500)
vuldb·2026-06-12·CVSS 6.5
CVE-2026-7184 [MEDIUM] Mattermost up to 11.6.x Remote Cluster API insertion of sensitive information into sent data (EUVD-2026-36500)
A vulnerability described as problematic has been identified in Mattermost up to 10.11.15/10.11.16/11.5.4/11.6.1/11.6.x. This vulnerability affects unknown code of the component Remote Cluster API. Executing a manipulation can lead to insertion of sensitive information into sent data.
This vulnerability appears as CVE-2026-7184. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-12
Published