CVE-2026-9597

CVE-2026-9597 is a medium-severity vulnerability in Mattermost Mattermost Server with a CVSS 3.x base score of 5.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-305.

Key facts

Description

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681

Frequently asked questions

What is CVE-2026-9597?
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681
How severe is CVE-2026-9597?
CVE-2026-9597 has a CVSS 3.x base score of 5.4, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability none.
Is CVE-2026-9597 being actively exploited?
It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (4th percentile), an estimate of the probability of exploitation in the next 30 days.
What products are affected by CVE-2026-9597?
CVE-2026-9597 affects Mattermost Mattermost Server. See the affected-products list for the exact vulnerable versions.
How do I fix CVE-2026-9597?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
When was CVE-2026-9597 published?
CVE-2026-9597 was published on 2026-07-13.

References

Affected products (1)

More vulnerabilities in Mattermost Mattermost Server

All CVEs affecting Mattermost Mattermost Server →

Other CWE-305 vulnerabilities

Browse all CWE-305 vulnerabilities →