CVE-2026-3636: Sanitize team member data returned by API
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team member data when returned via API to users without elevated permissions which allows a user without permissions to get data about team members roles via invoking various team API endpoints.. Mattermost Advisory ID: MMSA-2026-00626
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3636?
CVE-2026-3636 has a medium severity rating of 4.3.
How do I fix CVE-2026-3636?
To fix CVE-2026-3636, update Mattermost to versions 11.7.0, 11.6.1, 11.5.4, 11.4.5, or 10.11.15 or higher.
What impact does CVE-2026-3636 have?
CVE-2026-3636 allows unauthorized users to access sensitive team member data through API calls.
Which versions of Mattermost are affected by CVE-2026-3636?
Mattermost versions 11.6.x up to 11.6.0, 11.5.x up to 11.5.3, 11.4.x up to 11.4.4, and 10.11.x up to 10.11.14 are affected by CVE-2026-3636.
What type of vulnerability is CVE-2026-3636?
CVE-2026-3636 is classified as an infoleak vulnerability due to improper sanitization of team member data.