Guest users can view group member IDs without respecting view restrictions
Published Mar 26, 2026
4.3
MEDIUMCVSS 3.1
EPSS 0.27%
Description
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restrictions when retrieving group member IDs, which allows authenticated guest users to enumerate user IDs outside their allowed visibility scope via the group retrieval endpoint.. Mattermost Advisory ID: MMSA-2026-00594
Affected products
-
- Version 10.11.0StatusaffectedConstraints<=10.11.10
- Version 11.2.0StatusaffectedConstraints<=11.2.2
- Version 11.3.0StatusaffectedConstraints<=11.3.1
- Version 11.4.0StatusaffectedConstraints<=11.4.0
- Version 10.11.11StatusunaffectedConstraints-
- Version 11.2.3StatusunaffectedConstraints-
- Version 11.3.2StatusunaffectedConstraints-
- Version 11.4.1StatusunaffectedConstraints-
- Version 11.5.0StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Mattermost | Mattermost | unaffected |
|
- ≥ 10.11.0 · < 10.11.11
- ≥ 11.2.0 · < 11.2.3
- ≥ 11.3.0 · < 11.3.2
- 11.4.0
No data.
No Red Hat product state for this CVE.
github.com/mattermost/mattermost/server/v8
Go
Introduced 8.0.0-20260105080200-d27a2195068d Fixed 8.0.0-20260217110922-b7d4a1f1f59bgithub.com/mattermost/mattermost-server
Go
Introduced 10.11.0-rc1+incompatible Fixed 10.11.11+incompatiblegithub.com/mattermost/mattermost-server
Go
Introduced 11.2.0-rc1+incompatible Fixed 11.2.3+incompatiblegithub.com/mattermost/mattermost-server
Go
Introduced 11.3.0-rc1+incompatible Fixed 11.3.2+incompatiblegithub.com/mattermost/mattermost-server
Go
Introduced 11.4.0+incompatible Fixed 11.4.1+incompatiblegithub.com/mattermost/mattermost-server/v5
Go
Introduced 0 Fixed not fixedgithub.com/mattermost/mattermost-server/v6
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/mattermost/mattermost/server/v8 | 8.0.0-20260105080200-d27a2195068d | 8.0.0-20260217110922-b7d4a1f1f59b |
| Go | github.com/mattermost/mattermost-server | 10.11.0-rc1+incompatible | 10.11.11+incompatible |
| Go | github.com/mattermost/mattermost-server | 11.2.0-rc1+incompatible | 11.2.3+incompatible |
| Go | github.com/mattermost/mattermost-server | 11.3.0-rc1+incompatible | 11.3.2+incompatible |
| Go | github.com/mattermost/mattermost-server | 11.4.0+incompatible | 11.4.1+incompatible |
| Go | github.com/mattermost/mattermost-server/v5 | 0 | not fixed |
| Go | github.com/mattermost/mattermost-server/v6 | 0 | not fixed |
Remediation
Vendor solution
Update Mattermost to versions 11.5.0, 11.2.3, 10.11.11, 11.4.1, 11.3.2 or higher.
References (3)
- https://github.com/advisories/GHSA-mpc7-mm28-f6wq Advisory
- https://mattermost.com/security-updates vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-3115
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-mpc7-mm28-f6wq | Advisory | |
| https://mattermost.com/security-updates | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-3115 |
Change history (0)
No recorded changes yet.