Back

MEDIUM

Global session revocation does not invalidate active WebSocket connections

Published Jun 22, 2026

Description

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached authentication state for active WebSocket connections during global session revocation, which allows a user with an existing WebSocket connection to remain authenticated and continue receiving real-time events until the cached session expires or the client reconnects.. Mattermost Advisory ID: MMSA-2026-00664

Affected products

Remediation

Vendor solution

Update Mattermost to versions 11.8.0, 11.7.1, 11.6.3, 11.5.6, 10.11.18 or higher.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published Jun 22, 2026
Updated Jun 22, 2026
Reserved May 21, 2026
CISA Vulnrichment
Updated Jun 22, 2026
NVD
Status Analyzed
Modified Jun 23, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-H998-HXXJ-8Q83