Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9820

Опубликовано: 13 июл. 2026
Источник: nvd
CVSS3: 3.8
EPSS Низкий

Описание

Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Версия от 10.11.0 (включая) до 10.11.20 (исключая)
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Версия от 11.7.0 (включая) до 11.7.3 (исключая)

EPSS

Процентиль: 5%
0.00152
Низкий

3.8 Low

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 3.8
debian
18 дней назад

Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sani ...

CVSS3: 3.8
github
18 дней назад

Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost Advisory ID: MMSA-2026-00671

EPSS

Процентиль: 5%
0.00152
Низкий

3.8 Low

CVSS3

Дефекты

CWE-862