Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5mr9-crcg-8wh2 | Mattermost fails to use consistent error responses when handling the /mute command |
Solution
Update Mattermost to versions 11.4.0, 11.3.1, 11.2.3, 10.11.11 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Wed, 18 Mar 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Server
|
Tue, 17 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Mon, 16 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error messages for nonexistent versus private channels. Mattermost Advisory ID: MMSA-2026-00588 | |
| Title | Private channel enumeration via /mute slash command | |
| Weaknesses | CWE-203 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-03-16T18:39:14.064Z
Reserved: 2026-02-13T10:01:31.918Z
Link: CVE-2026-21386
Updated: 2026-03-16T18:39:06.523Z
Status : Analyzed
Published: 2026-03-16T15:16:20.927
Modified: 2026-03-18T13:53:15.357
Link: CVE-2026-21386
No data.
OpenCVE Enrichment
Updated: 2026-03-17T09:52:44Z
Github GHSA