Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-9597— Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint

CVSS 5.4 · Medium EPSS 0.14% · P4

Possible ATT&CK Techniques 1AI

T1078 · Valid Accounts

Affected Version Matrix 5

VendorProductVersion RangeStatus
MattermostMattermost11.7.0≤ 11.7.2affected
11.6.0≤ 11.6.4affected
11.8.0unaffected
11.7.3unaffected
11.6.5unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-9597

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint
Source: NVD (National Vulnerability Database)
Vulnerability Description
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
使用基本弱点进行的认证绕过
Source: NVD (National Vulnerability Database)
Vulnerability Title
Mattermost 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mattermost是美国Mattermost公司开源的一个开源协作平台。 Mattermost 11.7.2及之前的11.7.x版本和11.6.4及之前的11.6.x版本存在授权问题漏洞,该漏洞源于在魔法链接令牌登录路径中未能验证来宾账户是否已被停用,允许已停用的来宾用户通过停用前签发的魔法链接令牌获取完全有效的会话。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
MattermostMattermost 11.7.0 ~ 11.7.2 -

II. Public POCs for CVE-2026-9597

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9597

登录查看更多情报信息。

Same Patch Batch · Mattermost · 2026-07-13 · 10 CVEs total

CVE-2026-68506.5 MEDIUMCrafted message attachment causes client-side denial of service via markdown parser regex
CVE-2026-101066.5 MEDIUMUnauthorized users can trigger interactive post actions in private channels via action coo
CVE-2026-95715.9 MEDIUMDeactivated user accounts can continue to obtain valid OAuth access tokens via refresh tok
CVE-2026-100855.4 MEDIUMOrdinary group/direct message member can enable group_constrained and remove all channel p
CVE-2026-97084.9 MEDIUMIncoming webhook user attribution via unvalidated webhook owner
CVE-2026-65414.3 MEDIUMUnscoped updates to other playbooks' metric configuration
CVE-2026-98244.3 MEDIUMRemote cluster metadata enumeration via /share-channel autocomplete
CVE-2026-101034.3 MEDIUMAuthenticated remote cluster can modify or delete posts it does not own in Mattermost Conn
CVE-2026-98203.8 LOWMattermost schemes teams endpoint exposes private team invite IDs

IV. Related Vulnerabilities

V. Comments for CVE-2026-9597

No comments yet


Leave a comment