PT-2026-33036 · Mattermost · Mattermost

Daw10

·

Published

2026-04-15

·

Updated

2026-04-17

·

CVE-2026-27769

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 10.11.x through 10.11.12
Description Improper validation of user ownership within the Connected Workspaces feature allows a malicious remote server to change the displayed status of local users via the Connected Workspaces API.
Recommendations Update to a version later than 10.11.12.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05630
CVE-2026-27769
GHSA-MXXH-FMJQ-J6X4

Affected Products

Mattermost