CVE-2026-1629: Mattermost Server

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel access which allows the user to continue viewing private channel content via previously cached permalink previews until cache reset or relogin.. Mattermost Advisory ID: MMSA-2026-00580

Affected products

  • Mattermost Mattermost Server: from 10.11.0, before 10.11.11 (fixed in 10.11.11)

Published 2026-03-16. Last modified 2026-06-17.