Medium severity5.3NVD Advisory· Published Jun 12, 2026· Updated Jun 15, 2026
CVE-2026-6046
CVE-2026-6046
Description
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot registration belongs to a bot account, which allows an unprivileged attacker to intercept private messages sent by plugins via direct message channels by pre-registering a user account with a predictable plugin bot username.. Mattermost Advisory ID: MMSA-2026-00649
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/mattermost/mattermost-serverGo | >= 11.6.0, < 11.6.1 | 11.6.1 |
github.com/mattermost/mattermost-serverGo | >= 11.5.0, < 11.5.5 | 11.5.5 |
github.com/mattermost/mattermost-serverGo | >= 10.11.0, < 10.11.17 | 10.11.17 |
github.com/mattermost/mattermost/server/v8Go | >= 8.0.0-20250731163400-5b955468ea1e, < 8.0.0-20260428151657-c79c3831061a | 8.0.0-20260428151657-c79c3831061a |
Affected products
3<=11.6.1 || <=11.5.4 || <=10.11.15 || <=10.11.16+ 1 more
- (no CPE)range: <=11.6.1 || <=11.5.4 || <=10.11.15 || <=10.11.16
- (no CPE)range: >=11.6.0 <=11.6.1 or >=11.5.0 <=11.5.4 or >=10.11.0 <=10.11.16
- osv-coordsRange: < 0.0.20260827T195228-160000.1.1
Patches
Vulnerability mechanics
References
17- github.com/advisories/GHSA-3vmp-whvv-5v9vghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-6046ghsaADVISORY
- github.com/mattermost/mattermost/commit/3be10297c14d272f273d747af70728f9d03c60ecghsaWEB
- github.com/mattermost/mattermost/commit/98f9778cec1e7f3d97b3d4692fb91f8e7b659972ghsaWEB
- github.com/mattermost/mattermost/commit/aba9339a24d4b287edd77377c19901d6e341bb96ghsaWEB
- github.com/mattermost/mattermost/commit/c79c3831061a0880c0962c7d567c9e24dd35f44cghsaWEB
- github.com/mattermost/mattermost/commit/f706d1f01e6dfe62cab86c1d257f237daa78106aghsaWEB
- github.com/mattermost/mattermost/pull/36064ghsaWEB
- github.com/mattermost/mattermost/pull/36305ghsaWEB
- github.com/mattermost/mattermost/pull/36317ghsaWEB
- github.com/mattermost/mattermost/pull/36318ghsaWEB
- github.com/mattermost/mattermost/pull/36320ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v10.11.16ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v11.5.5ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v11.6.2ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v11.7.0ghsaWEB
- mattermost.com/security-updatesnvdWEB
News mentions
1- Mattermost Discloses 7 CVEs: Privilege Escalation, Token Theft, and Federated File WriteVypr Intelligence · Jun 12, 2026