Low severity2.7NVD Advisory· Published Feb 27, 2023· Updated Jun 17, 2026
CVE-2023-27266
CVE-2023-27266
Description
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
45.12.0+ 2 more
- (no CPE)range: 5.12.0
- cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*range: >=5.12.0,<7.7.0
- (no CPE)
Patches
Vulnerability mechanics
References
1- mattermost.com/security-updates/nvdVendor Advisory
News mentions
0No linked articles in our index yet.