Back

LOW

Improper Permission Check Allows User Manager to Deactivate Bot Accounts

Published Jun 22, 2026

Description

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integrations access to deactivate bot accounts via the PUT /api/v4/users/{id}/active API endpoint.. Mattermost Advisory ID: MMSA-2026-00667

Affected products

Remediation

Vendor solution

Update Mattermost to versions 11.8.0, 11.7.1, 10.11.18 or higher.

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Mattermost
Published Jun 22, 2026
Updated Jun 22, 2026
Reserved May 7, 2026

CISA Vulnrichment

Updated Jun 22, 2026

NVD

Status Analyzed
Modified Jun 23, 2026

Red Hat

No data

ENISA EUVD

Assigner Mattermost
Published Jun 22, 2026
Updated Jun 22, 2026