CVE-2026-10085: Ordinary group/direct message member can enable group_constrained and remove all channel participants
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the groupconstrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel patch API.. Mattermost Advisory ID: MMSA-2026-00688
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.3 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.20 - Compensating control
As a mitigating step, restrict access to the channel patch API so that only authorized administrators (not ordinary group/direct message members) can use it to modify participants.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10085?
CVE-2026-10085 has a medium severity rating of 5.4.
How do I fix CVE-2026-10085?
To fix CVE-2026-10085, update Mattermost to version 11.7.3, 11.6.5, or 10.11.20 or later.
What impact does CVE-2026-10085 have on Mattermost users?
CVE-2026-10085 allows ordinary members to remove all participants from a conversation in channels with the group_constrained flag.
Which Mattermost versions are affected by CVE-2026-10085?
Mattermost versions 11.7.2 and earlier, 11.6.4 and earlier, and 10.11.19 and earlier are affected by CVE-2026-10085.
What type of vulnerability is CVE-2026-10085?
CVE-2026-10085 is a vulnerability that affects the permission model, allowing unauthorized actions by regular users.