CVE-2026-7184: Mattermost Remote Cluster PATCH API Leaks Authentication Tokens
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API response on PATCH operations, which allows authenticated users with the {{managesecureconnections}} permission to obtain remote cluster authentication tokens via a PATCH request to the remote cluster endpoint.. Mattermost Advisory ID: MMSA-2026-00662
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.0Patch MMSA-2026-00662 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.2Patch MMSA-2026-00662 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.5.5Patch MMSA-2026-00662 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.17Patch MMSA-2026-00662
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7184?
The severity of CVE-2026-7184 is medium with a score of 6.5.
How do I fix CVE-2026-7184?
To fix CVE-2026-7184, update Mattermost to versions 11.7.0, 11.6.2, 11.5.5, 10.11.17 or higher.
What impact does CVE-2026-7184 have?
CVE-2026-7184 allows authenticated users with the manage_secure_connections permission to obtain remote cluster authentication tokens.
Which versions of Mattermost are affected by CVE-2026-7184?
Mattermost versions 11.6.x up to 11.6.1, 11.5.x up to 11.5.4, and 10.11.x up to 10.11.15 are affected by CVE-2026-7184.
What action should you take if you are running an affected version of Mattermost for CVE-2026-7184?
If running an affected version of Mattermost for CVE-2026-7184, you should immediately upgrade to the latest secure version.