What is CVE-2026-9693?
CVE-2026-9693 affects Mattermost versions 10.11.x up to 10.11.20 and 11.7.x up to 11.7.5, where thread membership records are not removed when a user leaves a team. This flaw allows a previously removed user to view private channel thread root post content and metadata upon rejoining the team. Affected instances should be updated to the latest patched versions immediately.
Azərbaycanca: CVE-2026-9693 zəifliyi Mattermost-un 10.11.x (≤10.11.20) və 11.7.x (≤11.7.5) versiyalarında aşkarlanıb. İstifadəçi komandadan çıxarıldıqda thread membership qeydləri silinmir, nəticədə həmin istifadəçi yenidən dəvət olunduqda özəl kanallardakı thread root post məzmununa baxa bilir. Təsirə məruz qalan sistemlər dərhal göstərilən versiyalardan ən son təhlükəsizlik yamalarına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Mattermost
FAQ2
Which Mattermost versions are affected by CVE-2026-9693?
CVE-2026-9693 affects Mattermost versions 10.11.x up to 10.11.20 and 11.7.x up to 11.7.5.
What information can a user access by exploiting CVE-2026-9693?
The user can view private channel thread root post content and metadata upon rejoining the team.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.