CVE-2026-21386: Private channel enumeration via /mute slash command
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error messages for nonexistent versus private channels. Mattermost Advisory ID: MMSA-2026-00588
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21386?
The severity of CVE-2026-21386 is classified as a high vulnerability due to its potential for unauthorized access to private channel information.
How do I fix CVE-2026-21386?
To fix CVE-2026-21386, update to Mattermost version 11.3.1 or later, 11.2.3 or later, or 10.11.11 or later.
What types of Mattermost versions are affected by CVE-2026-21386?
Mattermost versions 11.3.0 and earlier, 11.2.2 and earlier, and 10.11.10 and earlier are affected by CVE-2026-21386.
What is the impact of CVE-2026-21386 on Mattermost users?
CVE-2026-21386 allows authenticated users to enumerate private channels they do not have rights to access, leading to potential privacy breaches.
Is there a workaround for CVE-2026-21386 if I cannot update immediately?
Currently, there are no documented workarounds for CVE-2026-21386, so it is recommended to apply the available updates as soon as possible.