PT-2026-41650 · Mattermost · Gitlab Plugin
Daw10
·
Published
2026-05-18
·
Updated
2026-05-18
·
CVE-2026-3117
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Mattermost Plugins versions prior to 11.5
Description
The Gitlab plugin fails to properly check for permissions when processing commands. This allows standard users to uninstall instances or configure webhook connections by using the "/gitlab instance {option}" and "/gitlab webhook {option}" commands.
Recommendations
Update to a version later than 11.5.
As a temporary workaround, restrict the use of the "/gitlab instance" and "/gitlab webhook" commands.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab Plugin