news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-10085

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
5.4 Medium
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Risk score
43.2
Published
2026-07-13
Status
Published

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel patch API.. Mattermost Advisory ID: MMSA-2026-00688

Weaknesses

CWE-862

Coverage 1

Advisories and references