Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Improper Permission Check Allows User Manager to Deactivate Bot Accounts
Vulnerability Description
Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no Integrations access to deactivate bot accounts via the PUT /api/v4/users/{id}/active API endpoint.. Mattermost Advisory ID: MMSA-2026-00667
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
授权机制不正确
Vulnerability Title
Mattermost 授权问题漏洞
Vulnerability Description
Mattermost是美国Mattermost公司开源的一个开源协作平台。 Mattermost 11.7.0及之前版本和10.11.17及之前版本存在授权问题漏洞,该漏洞源于用户活跃状态端点未强制执行机器人特定权限检查,可能导致具有用户管理写入权限但没有集成访问权限的用户管理器通过PUT /api/v4/users/{id}/active API端点停用机器人账户。
CVSS Information
N/A
Vulnerability Type
N/A