CVE-2026-9824: Remote cluster metadata enumeration via /share-channel autocomplete
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the managesharedchannels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster connection metadata via slash command autocomplete.. Mattermost Advisory ID: MMSA-2026-00676
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.3 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.20
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9824?
The severity of CVE-2026-9824 is medium with a CVSS score of 4.3.
How do I fix CVE-2026-9824?
To fix CVE-2026-9824, upgrade Mattermost to version 11.7.3 or later for the 11.7.x series, version 11.6.5 or later for the 11.6.x series, and version 10.11.20 or later for the 10.11.x series.
What does CVE-2026-9824 exploit?
CVE-2026-9824 exploits the lack of permission checks on the /share-channel autocomplete handler, allowing unauthorized users to enumerate remote cluster connection metadata.
Which versions of Mattermost are affected by CVE-2026-9824?
Mattermost versions 11.7.2 and earlier, 11.6.4 and earlier, and 10.11.19 and earlier are affected by CVE-2026-9824.
Is authentication required to exploit CVE-2026-9824?
Yes, exploitation of CVE-2026-9824 requires that the attacker is an authenticated user.