Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace
Low severity
GitHub Reviewed
Published
Apr 17, 2026
to the GitHub Advisory Database
•
Updated Apr 28, 2026
Package
Affected versions
>= 8.0.0-20250721062209-4952acea88ce, < 8.0.0-20260316060126-bc1a2b34b1f9
Patched versions
8.0.0-20260316060126-bc1a2b34b1f9
Description
Published by the National Vulnerability Database
Apr 15, 2026
Published to the GitHub Advisory Database
Apr 17, 2026
Reviewed
Apr 28, 2026
Last updated
Apr 28, 2026
Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed status of local users via the Connected Workspaces API. Mattermost Advisory ID: MMSA-2026-00603.
References