CVE-2026-8074: Improper Permission Check Allows User Manager to Deactivate Bot Accounts
Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integrations access to deactivate bot accounts via the PUT /api/v4/users/{id}/active API endpoint.. Mattermost Advisory ID: MMSA-2026-00667
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.1 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8074?
The severity of CVE-2026-8074 is rated low with a score of 3.8.
How do I fix CVE-2026-8074?
To fix CVE-2026-8074, upgrade Mattermost to versions 11.7.1 or later, or 10.11.18 or later.
What software is affected by CVE-2026-8074?
CVE-2026-8074 affects Mattermost versions 11.7.x up to 11.7.0 and 10.11.x up to 10.11.17.
What does CVE-2026-8074 exploit?
CVE-2026-8074 exploits improper permission checks that enable a User Manager to deactivate bot accounts.
What types of access does a User Manager need to exploit CVE-2026-8074?
A User Manager only needs user management write access to exploit CVE-2026-8074, without needing Integrations access.