CVE-2026-9571
published 2026-07-13CVE-2026-9571: Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.17%
7.1th percentile
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint.. Mattermost Advisory ID: MMSA-2026-00680
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mattermost | mattermost | 10.11.0 – 10.11.19 | — |
| mattermost | mattermost | 11.6.0 – 11.6.4 | — |
| mattermost | mattermost | 11.7.0 – 11.7.2 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.20 | 10.11.20 |
| mattermost | mattermost_server | >= 11.6.0 < 11.6.5 | 11.6.5 |
| mattermost | mattermost_server | >= 11.7.0 < 11.7.3 | 11.7.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in po
ghsa_unreviewed·2026-07-13
CVE-2026-9571 [MEDIUM] CWE-305 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in po
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint.. Mattermost Advisory ID: MMSA-2026-00680
VulDB
Mattermost up to 10.11.19/11.6.4/11.7.2 OAuth Refresh Token Grant Endpoint privilege escalation (WID-SEC-2026-1932)
vuldb·2026-07-13·CVSS 6.5
CVE-2026-9571 [MEDIUM] Mattermost up to 10.11.19/11.6.4/11.7.2 OAuth Refresh Token Grant Endpoint privilege escalation (WID-SEC-2026-1932)
A vulnerability classified as critical was found in Mattermost up to 10.11.19/11.6.4/11.7.2. This vulnerability affects unknown code of the component OAuth Refresh Token Grant Endpoint. Such manipulation leads to privilege escalation.
This vulnerability is referenced as CVE-2026-9571. It is possible to launch the attack remotely. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-13
Published