Mattermost OAuth Token Invalidation on Deactivation (11.7.2/11.6.4/10.11.19)
CVE-2026-9571 Published on July 13, 2026
Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in Mattermost
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint.. Mattermost Advisory ID: MMSA-2026-00680
Vulnerability Analysis
CVE-2026-9571 can be exploited with network access, and requires user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Authentication Bypass by Primary Weakness
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
Products Associated with CVE-2026-9571
Want to know whenever a new CVE is published for MatterMost? stack.watch will email you.
Affected Versions
Mattermost:- Version 11.7.0, <= 11.7.2 is affected.
- Version 11.6.0, <= 11.6.4 is affected.
- Version 10.11.0, <= 10.11.19 is affected.
- Version 11.8.0 is unaffected.
- Version 11.7.3 is unaffected.
- Version 11.6.5 is unaffected.
- Version 10.11.20 is unaffected.