TROYANOSYVIRUS
Back to CVEs

CVE-2026-21386

MEDIUM
4.3

Description

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error messages for nonexistent versus private channels. Mattermost Advisory ID: MMSA-2026-00588

CVE Details

CVSS v3.1 Score4.3
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published3/16/2026
Last Modified3/18/2026
Sourcenvd
Honeypot Sightings0

Affected Products

mattermost:mattermost_server

Weaknesses (CWE)

CWE-203

References

https://mattermost.com/security-updates(responsibledisclosure@mattermost.com)

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.