Mattermost 11.6-11.7 MagicLink Session Hijack (Deactivated Guest)
CVE-2026-9597 Published on July 13, 2026
Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681
Vulnerability Analysis
CVE-2026-9597 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Authentication Bypass by Primary Weakness
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
Products Associated with CVE-2026-9597
Want to know whenever a new CVE is published for MatterMost? stack.watch will email you.
Affected Versions
Mattermost:- Version 11.7.0, <= 11.7.2 is affected.
- Version 11.6.0, <= 11.6.4 is affected.
- Version 11.8.0 is unaffected.
- Version 11.7.3 is unaffected.
- Version 11.6.5 is unaffected.