Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event.. Mattermost Advisory ID: MMSA-2026-00579

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Update Mattermost to versions 11.4.0, 11.3.1 or higher.


Workaround

No workaround given by the vendor.

References
History

Mon, 16 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event.. Mattermost Advisory ID: MMSA-2026-00579
Title Information Disclosure via WebSocket Event When Deleting Unrevealed Burn on Read Posts
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-03-16T13:49:55.812Z

Reserved: 2026-02-16T10:09:16.281Z

Link: CVE-2026-2578

cve-icon Vulnrichment

Updated: 2026-03-16T13:43:46.276Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-16T14:19:30.840

Modified: 2026-03-16T14:53:07.390

Link: CVE-2026-2578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses