CVE-2026-9597: Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.3 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.5 - Compensating control
Ensure magic-link tokens are invalidated/expired for any guest accounts that were deactivated before the Mattermost upgrade to prevent use of pre-deactivation tokens.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9597?
CVE-2026-9597 has a medium severity rating of 5.4.
How do I fix CVE-2026-9597?
To fix CVE-2026-9597, upgrade Mattermost to the latest version beyond 11.7.2 or 11.6.4.
What does CVE-2026-9597 exploit?
CVE-2026-9597 exploits the failure of Mattermost to properly verify the status of guest accounts during magic-link token authentication.
Who is affected by CVE-2026-9597?
Deactivated guest accounts in Mattermost versions 11.7.x up to 11.7.2 and 11.6.x up to 11.6.4 are affected by CVE-2026-9597.
What are the potential impacts of CVE-2026-9597?
The potential impacts of CVE-2026-9597 include unauthorized session access for deactivated guest users through magic-link tokens.