Thread Membership Record Leak in Mattermost Team Threads API <10.11.20,<11.7.5
CVE-2026-9693 Published on August 17, 2026
Mattermost thread memberships persist after team removal, exposing private channel thread metadata on re-invite
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads API.. Mattermost Advisory ID: MMSA-2026-00682
Vulnerability Analysis
CVE-2026-9693 can be exploited with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Weakness Type
What is an Insufficient Cleanup Vulnerability?
The software does not properly "clean up" and remove temporary or supporting resources after they have been used.
CVE-2026-9693 has been classified to as an Insufficient Cleanup vulnerability or weakness.
Products Associated with CVE-2026-9693
Want to know whenever a new CVE is published for MatterMost? stack.watch will email you.
Affected Versions
Mattermost:- Version 10.11.0, <= 10.11.20 is affected.
- Version 11.7.0, <= 11.7.5 is affected.
- Version 11.9.0 is unaffected.
- Version 10.11.21 is unaffected.
- Version 11.7.6 is unaffected.