CVE-2026-3433: Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
(updated )
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to restrict role_updated websocket event broadcasts to members of the affected team or channel, which allows an authenticated attacker with guest-level access to observe permission scheme change notifications for private teams they are not a member of via the websocket connection. Mattermost Advisory ID: MMSA-2026-00616
References
- github.com/advisories/GHSA-rp4v-qc77-phm4
- github.com/mattermost/mattermost/commit/0a0ab0d54d899d308bd1352cc577036917500318
- github.com/mattermost/mattermost/commit/7425c6817bf244f976c729f8a73cecac8039a1e1
- github.com/mattermost/mattermost/commit/9408b98025d7364d7dfe7cdb28fcd109b1b595a6
- github.com/mattermost/mattermost/commit/a30a331a29b9766d46716d4252056d7b74e66da0
- github.com/mattermost/mattermost/pull/35497
- github.com/mattermost/mattermost/pull/36256
- github.com/mattermost/mattermost/pull/36257
- github.com/mattermost/mattermost/pull/36341
- github.com/mattermost/mattermost/releases/tag/v10.11.16
- github.com/mattermost/mattermost/releases/tag/v11.5.5
- github.com/mattermost/mattermost/releases/tag/v11.6.2
- github.com/mattermost/mattermost/releases/tag/v11.7.0
- mattermost.com/security-updates
- nvd.nist.gov/vuln/detail/CVE-2026-3433
Code Behaviors & Features
Detect and mitigate CVE-2026-3433 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →