CVE-2026-6689: Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
(updated )
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fail to enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation (the check was only applied on update/patch), which allows an authenticated user holding PermissionCreateTeam but not PermissionInviteUser on the resulting team to configure invite-controlled team settings (make the team publicly joinable via open invite and/or constrain membership via allowed domains) that they are not permitted to set on an existing team via POST /api/v4/teams with allow_open_invite: true and/or a non-empty allowed_domains in the request body.. Mattermost Advisory ID: MMSA-2026-00655
References
- github.com/advisories/GHSA-c28q-m4gf-vg4q
- github.com/mattermost/mattermost/commit/2dea05864024b3254fb28c5ed679592e2b7cd672
- github.com/mattermost/mattermost/commit/3a96344214b1a84df70d97052d46b6f2b40b0caa
- github.com/mattermost/mattermost/commit/479fc42d0ec6da48e76b59608233d90bfc69769d
- github.com/mattermost/mattermost/commit/7d6816abdfd170169f717aea43c5716a1f9ef6b0
- github.com/mattermost/mattermost/commit/977c791e5b54bc14fdb96a2b3dacc85da5d8c623
- github.com/mattermost/mattermost/pull/36188
- github.com/mattermost/mattermost/pull/36375
- github.com/mattermost/mattermost/pull/36383
- github.com/mattermost/mattermost/pull/36384
- github.com/mattermost/mattermost/pull/36402
- github.com/mattermost/mattermost/releases/tag/v10.11.16
- github.com/mattermost/mattermost/releases/tag/v11.5.5
- github.com/mattermost/mattermost/releases/tag/v11.6.2
- github.com/mattermost/mattermost/releases/tag/v11.7.0
- mattermost.com/security-updates
- nvd.nist.gov/vuln/detail/CVE-2026-6689
Code Behaviors & Features
Detect and mitigate CVE-2026-6689 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →