UNKNOWN Go
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server
GO-2026-6286 · CVE-2026-3433 · GHSA-rp4v-qc77-phm4
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server
References
- ADVISORY https://github.com/advisories/GHSA-rp4v-qc77-phm4
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-3433
- WEB https://github.com/mattermost/mattermost/commit/0a0ab0d54d899d308bd1352cc577036917500318
- WEB https://github.com/mattermost/mattermost/commit/7425c6817bf244f976c729f8a73cecac8039a1e1
- WEB https://github.com/mattermost/mattermost/commit/9408b98025d7364d7dfe7cdb28fcd109b1b595a6
- WEB https://github.com/mattermost/mattermost/commit/a30a331a29b9766d46716d4252056d7b74e66da0
- WEB https://github.com/mattermost/mattermost/pull/35497
- WEB https://github.com/mattermost/mattermost/pull/36256
- WEB https://github.com/mattermost/mattermost/pull/36257
- WEB https://github.com/mattermost/mattermost/pull/36341
- WEB https://github.com/mattermost/mattermost/releases/tag/v10.11.16
- WEB https://github.com/mattermost/mattermost/releases/tag/v11.5.5
- WEB https://github.com/mattermost/mattermost/releases/tag/v11.6.2
- WEB https://github.com/mattermost/mattermost/releases/tag/v11.7.0
- WEB https://mattermost.com/security-updates
Ready to move
Start Securing
Free, no credit card | First findings in minutes