PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3433 Mattermost CVE debrief

CVE-2026-3433 is a vulnerability in Mattermost, a self-hosted, open-source, and customizable platform for team communication. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. It was published on 2026-06-12T17:16:22.467Z and has not been modified since its publication.

Vendor
Mattermost
Product
Unknown
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-12
Original CVE updated
2026-06-18
Advisory published
2026-06-12
Advisory updated
2026-06-18

Who should care

Users of Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, and 10.11.x <= 10.11.16 should be aware of this vulnerability.

Technical summary

The vulnerability occurs because Mattermost fails to restrict role_updated websocket event broadcasts to members of the affected team or channel. This allows an authenticated attacker with guest-level access to observe permission scheme change notifications for private teams they are not a member of via the websocket connection.

Defensive priority

MEDIUM

Recommended defensive actions

  • Update to a version of Mattermost that is not vulnerable.

Evidence notes

The CVE was obtained from the NVD database. The Mattermost Advisory ID is MMSA-2026-00616.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-3433 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-3433

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-3433 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3433

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.