CVE-2026-9597: Mattermost Server
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681
Affected products
- Mattermost Mattermost Server: from 11.6.0, before 11.6.5 (fixed in 11.6.5); from 11.7.0, before 11.7.3 (fixed in 11.7.3)
Published 2026-07-13. Last modified 2026-07-13.