CVE-2026-8823: User Manager can demote bot accounts to guest without bot-management permission
Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard demote-user API.. Mattermost Advisory ID: MMSA-2026-00669
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.8.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.7.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.11.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8823?
CVE-2026-8823 has a low severity score of 3.8.
How do I fix CVE-2026-8823?
To fix CVE-2026-8823, upgrade to Mattermost version 11.7.1 or 10.11.18 or later.
What is the risk associated with CVE-2026-8823?
CVE-2026-8823 poses a risk of unauthorized demotion of bot accounts by lower-privileged administrators.
Which versions of Mattermost are affected by CVE-2026-8823?
Mattermost versions 11.7.x up to 11.7.0 and 10.11.x up to 10.11.17 are affected by CVE-2026-8823.
What is the main issue of CVE-2026-8823?
The main issue of CVE-2026-8823 is improper validation of bot accounts when demoting users to guests.