Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681
{
"cna_assigner": "Mattermost",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "11.7.0"
},
{
"last_affected": "11.7.2"
},
{
"introduced": "11.6.0"
},
{
"last_affected": "11.6.4"
}
],
"source": "AFFECTED_FIELD"
}
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/9xxx/CVE-2026-9597.json",
"cwe_ids": [
"CWE-305"
]
}