CVE-2026-3433: Mattermost fails to scope role_updated websocket events to authorized team and channel members
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to restrict roleupdated websocket event broadcasts to members of the affected team or channel which allows an authenticated attacker with guest-level access to observe permission scheme change notifications for private teams they are not a member of via the websocket connection.. Mattermost Advisory ID: MMSA-2026-00616
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.2 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.5.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.16 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.17 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Patch MMSA-2026-00616
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3433?
The severity of CVE-2026-3433 is rated medium with a score of 4.3.
How do I fix CVE-2026-3433?
To fix CVE-2026-3433, update Mattermost to versions 11.7.0, 11.6.2, 11.5.5, 10.11.16, 10.11.17 or higher.
What versions of Mattermost are affected by CVE-2026-3433?
CVE-2026-3433 affects Mattermost versions 11.6.x up to 11.6.1, 11.5.x up to 11.5.4, and 10.11.x up to 10.11.15.
What type of vulnerability is CVE-2026-3433 classified as?
CVE-2026-3433 is classified as an information leak vulnerability.
Who can exploit CVE-2026-3433?
An authenticated attacker with guest-level access can exploit CVE-2026-3433 to observe changes in permission schemes.