CVE-2026-6046: Plugin bot username conflict allows user account to be used as bot identity in Mattermost Server
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot registration belongs to a bot account, which allows an unprivileged attacker to intercept private messages sent by plugins via direct message channels by pre-registering a user account with a predictable plugin bot username.. Mattermost Advisory ID: MMSA-2026-00649
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 11.7.0 - Upgrade
Upgrade
mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 11.6.2 - Upgrade
Upgrade
mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 11.5.5 - Upgrade
Upgrade
mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 10.11.16 - Upgrade
Upgrade
mattermost/mattermost-serverto a version that resolves this vulnerability.Fixed in 10.11.17
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6046?
The severity of CVE-2026-6046 is medium with a CVSS score of 5.3.
How do I fix CVE-2026-6046?
To fix CVE-2026-6046, update Mattermost to versions 11.7.0, 11.6.2, 11.5.5, 10.11.16, 10.11.17 or higher.
What types of accounts are affected by CVE-2026-6046?
CVE-2026-6046 affects user accounts that can be improperly used as bot identities due to username conflicts.
What impact does CVE-2026-6046 have on Mattermost Server users?
CVE-2026-6046 allows unprivileged attackers to intercept private messages sent by plugins via direct message channels.
Which versions of Mattermost are vulnerable to CVE-2026-6046?
The vulnerable versions of Mattermost include 11.6.x up to 11.6.1, 11.5.x up to 11.5.4, and 10.11.x up to 10.11.15.