---
id: CVE-2026-10085
title: >-
  Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19
  fail to restrict the group_constrained channel flag to public and private
  channels that support group synchronization, which allows an ordinary group or
  direct m…
summary: >-
  Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19
  fail to restrict the group_constrained channel flag to public and private
  channels that support group synchronization, which allows an ordinary group or
  direct m…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-862
published: '2026-07-13'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-10085'
references:
  - url: 'https://mattermost.com/security-updates'
    label: responsibledisclosure@mattermost.com
tags:
  - nvd
ingestedAt: '2026-07-13T12:26:57.332Z'
epss: 0.00287
epssPercentile: 0.21515
---

## Overview

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member to remove all participants from the conversation via the channel patch API.. Mattermost Advisory ID: MMSA-2026-00688

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
