CVE-2026-9820: Mattermost schemes teams endpoint exposes private team invite IDs
Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.3 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.20
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9820?
The severity of CVE-2026-9820 is rated as low with a base score of 3.8.
How do I fix CVE-2026-9820?
To mitigate CVE-2026-9820, upgrade Mattermost to the latest version where the vulnerability has been addressed.
What versions of Mattermost are affected by CVE-2026-9820?
CVE-2026-9820 affects Mattermost versions 11.7.x up to 11.7.2 and 10.11.x up to 10.11.19.
What is the impact of CVE-2026-9820?
CVE-2026-9820 allows a user with the User Manager role to obtain private team invite IDs and potentially share access to private teams.
Is CVE-2026-9820 easily exploitable?
CVE-2026-9820 has a low attack complexity rating, meaning it can be exploited under certain conditions with minimal effort.