Authentication Bypass in Mattermost Affects User Meeting and Post Management
CVE-2026-0998
What is CVE-2026-0998?
A critical security issue in several versions of Mattermost and its Zoom plugin allows unauthorized users to access and control Zoom meetings. The vulnerability arises due to improper validation of user identity and post ownership in the /api/v1/askPMI API endpoint. This flaw enables attackers to start Zoom meetings impersonating any user, and manipulate or overwrite posts through direct API requests by providing coerced user IDs and post data. Organizations using affected versions are strongly encouraged to review the Mattermost security advisory and apply necessary patches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mattermost 11.1.0 <= 11.1.2
Mattermost 10.11.0 <= 10.11.9
Mattermost 11.2.0 <= 11.2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved