Mattermost Plugin Vulnerability Allows User Privilege Escalation
CVE-2026-0997

4.3MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
16 February 2026

What is CVE-2026-0997?

A vulnerability exists in Mattermost and its Zoom plugin where specific versions fail to validate authenticated users effectively. This oversight allows any logged-in user to manipulate Zoom meeting restrictions for various channels by sending specially crafted API requests to the vulnerable endpoint {{/plugins/zoom/api/v1/channel-preference}}. This could potentially lead to unauthorized access and alterations of meetings, thereby compromising the integrity of user communications within the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Mattermost 11.1.0 <= 11.1.2

Mattermost 10.11.0 <= 10.11.9

Mattermost 11.2.0 <= 11.2.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daw10
.