Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to via a race condition in the /common_teams API endpoint.. Mattermost Advisory ID: MMSA-2025-00549
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2xf7-hmf6-p64j Mattermost doesn't properly validate channel membership at the time of data retrieval
Fixes

Solution

Update Mattermost to versions 11.3.0, 10.11.10 or higher.


Workaround

No workaround given by the vendor.

References
History

Fri, 13 Feb 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Fri, 13 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Feb 2026 10:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to via a race condition in the /common_teams API endpoint.. Mattermost Advisory ID: MMSA-2025-00549
Title Time-of-check time-of-use vulnerability in common teams API
Weaknesses CWE-367
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-02-13T17:02:25.985Z

Reserved: 2026-01-15T11:34:00.225Z

Link: CVE-2026-20796

cve-icon Vulnrichment

Updated: 2026-02-13T17:01:43.299Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-13T11:16:10.280

Modified: 2026-02-13T14:23:48.007

Link: CVE-2026-20796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-13T21:28:43Z

Weaknesses