CVE-2026-8074
published 2026-06-22CVE-2026-8074: Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a…
PriorityP416low3.8CVSS 3.1
AVNACLPRHUINSUCNILAL
EPSS
0.19%
9.0th percentile
Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integrations access to deactivate bot accounts via the PUT /api/v4/users/{id}/active API endpoint.. Mattermost Advisory ID: MMSA-2026-00667
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mattermost | mattermost | 10.11.0 – 10.11.17 | — |
| mattermost | mattermost | 11.7.0 – 11.7.0 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.18 | 10.11.18 |
| mattermost | mattermost_server | >= 11.7.0 < 11.7.1 | 11.7.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write acce
ghsa_unreviewed·2026-06-22
CVE-2026-8074 [LOW] CWE-863 Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write acce
Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integrations access to deactivate bot accounts via the PUT /api/v4/users/{id}/active API endpoint.. Mattermost Advisory ID: MMSA-2026-00667
VulDB
Mattermost up to 10.11.17/11.7.0/11.7.x User Active Status Endpoint authorization
vuldb·2026-06-22·CVSS 3.8
CVE-2026-8074 [LOW] Mattermost up to 10.11.17/11.7.0/11.7.x User Active Status Endpoint authorization
A vulnerability identified as problematic has been detected in Mattermost up to 10.11.17/11.7.0/11.7.x. This impacts an unknown function of the component User Active Status Endpoint. The manipulation leads to incorrect authorization.
This vulnerability is traded as CVE-2026-8074. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-22
Published