Project Subscriptions
No data.
No advisories yet.
Solution
Update Mattermost to versions 11.4.0, 11.3.1, 11.2.3, 10.11.11 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Mon, 16 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error messages for nonexistent versus private channels. Mattermost Advisory ID: MMSA-2026-00588 | |
| Title | Private channel enumeration via /mute slash command | |
| Weaknesses | CWE-203 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-03-16T18:39:14.064Z
Reserved: 2026-02-13T10:01:31.918Z
Link: CVE-2026-21386
Updated: 2026-03-16T18:39:06.523Z
Status : Received
Published: 2026-03-16T15:16:20.927
Modified: 2026-03-16T15:16:20.927
Link: CVE-2026-21386
No data.
OpenCVE Enrichment
No data.