Medium severity6.5NVD Advisory· Published Jun 12, 2026· Updated Jun 15, 2026
CVE-2026-7184
CVE-2026-7184
Description
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated users with the {{manage_secure_connections}} permission to obtain remote cluster authentication tokens via a PATCH request to the remote cluster endpoint.. Mattermost Advisory ID: MMSA-2026-00662
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/mattermost/mattermost-serverGo | >= 11.6.0, < 11.6.1 | 11.6.1 |
github.com/mattermost/mattermost-serverGo | >= 11.5.0, < 11.5.5 | 11.5.5 |
github.com/mattermost/mattermost-serverGo | >= 10.11.0, < 10.11.16 | 10.11.16 |
github.com/mattermost/mattermost/server/v8Go | >= 8.0.0-20250731163400-5b955468ea1e, < 8.0.0-20260428142921-bd8fc9222672 | 8.0.0-20260428142921-bd8fc9222672 |
Affected products
3>=11.6.0,<=11.6.1 OR >=11.5.0,<=11.5.4 OR >=10.11.0,<=10.11.15+ 1 more
- (no CPE)range: >=11.6.0,<=11.6.1 OR >=11.5.0,<=11.5.4 OR >=10.11.0,<=10.11.15
- (no CPE)range: >= 11.6.0, <= 11.6.1 || >= 11.5.0, <= 11.5.4 || >= 10.11.0, <= 10.11.15
- osv-coordsRange: < 0.0.20260827T195228-160000.1.1
Patches
Vulnerability mechanics
References
17- github.com/advisories/GHSA-9p44-r552-4wp9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-7184ghsaADVISORY
- github.com/mattermost/mattermost/commit/1a0643df00c1f51a3b7e919eec034eaf955f612fghsaWEB
- github.com/mattermost/mattermost/commit/6fd49f56b5920569218fd2fc76d8ae802942f274ghsaWEB
- github.com/mattermost/mattermost/commit/bd8fc92226726da06c8fabaef568cc9ebaee1cb8ghsaWEB
- github.com/mattermost/mattermost/commit/c5e67e28271c23cb585fe1a30ae81defcde848d6ghsaWEB
- github.com/mattermost/mattermost/commit/cad3e8e51a4d8627af6442f9df8ae3667fac7fc1ghsaWEB
- github.com/mattermost/mattermost/pull/36288ghsaWEB
- github.com/mattermost/mattermost/pull/36306ghsaWEB
- github.com/mattermost/mattermost/pull/36310ghsaWEB
- github.com/mattermost/mattermost/pull/36311ghsaWEB
- github.com/mattermost/mattermost/pull/36313ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v10.11.16ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v11.5.5ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v11.6.2ghsaWEB
- github.com/mattermost/mattermost/releases/tag/v11.7.0ghsaWEB
- mattermost.com/security-updatesnvdWEB
News mentions
1- Mattermost Discloses 7 CVEs: Privilege Escalation, Token Theft, and Federated File WriteVypr Intelligence · Jun 12, 2026