LOW 3.8 Go
Mattermost has an Incorrect Authorization issue
GHSA-xmfh-3ccg-c9fx · CVE-2026-8823
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard demote-user API.. Mattermost Advisory ID: MMSA-2026-00669
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-8823
- WEB https://github.com/mattermost/mattermost/pull/36487
- WEB https://github.com/mattermost/mattermost/commit/7972fc53f5c0b0175879a9737308a87b42db1f0b
- WEB https://github.com/mattermost/mattermost/commit/9bd77d3fc4d2af3f7f0259a205174e76a1a276e1
- WEB https://github.com/mattermost/mattermost/commit/c9bf3609fb9a3e5c2de94c50742c9b91fd723e3d
- WEB https://github.com/mattermost/mattermost/commit/d9a55e394cd5bc15edb49e9606bec8fec03ac4c6
- WEB https://docs.mattermost.com/security-guide/security-updates
- PACKAGE https://github.com/mattermost/mattermost
- WEB https://github.com/mattermost/mattermost/releases/tag/v10.11.18
- WEB https://github.com/mattermost/mattermost/releases/tag/v11.7.1
Ready to move
Start Securing
Free, no credit card | First findings in minutes