CVE-2026-9597: Mattermost Server

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681

Affected products

  • Mattermost Mattermost Server: from 11.6.0, before 11.6.5 (fixed in 11.6.5); from 11.7.0, before 11.7.3 (fixed in 11.7.3)

Published 2026-07-13. Last modified 2026-07-13.