Generated remediation guidance and an executive summary. No account required.
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invites to expose access to local channels, when shared channels are enabled, which allows a malicious remote to send an invite with the ID of an existing local channel, and that local channel will then become shared without the consent of the local admin.
Cite this page
CVE-2024-39777. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2024-39777
Use CWE-284, Mattermost vendor hub and Mattermost product page to widen CVE-2024-39777 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-39274, CVE-2024-39832 and CVE-2024-42411 for nearby disclosures in the same product family.