Mattermost Group Constrained Channel Flag Vulnerability in Channel Patch API

Vulnerability

A vulnerability exists in Mattermost versions 11.7.x through 11.7.2, 11.6.x through 11.6.4, and 10.11.x through 10.11.19. The issue arises because these versions do not properly restrict the group_constrained channel flag to public and private channels that allow group synchronization. As a result, a regular member of a group or direct message can use the channel patch API to remove all participants from the conversation.

Impact

Exploitation of this vulnerability allows a group or direct message member to remove all participants from the conversation, disrupting communication.

Remediation

Users can upgrade to Mattermost versions 11.8.0, 11.7.4, or 11.6.5 to address this vulnerability.

Added: Jul 13, 2026, 9:32 AM
Updated: Jul 13, 2026, 9:32 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
5.2
remediation
7.7
relevance
9.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.