Authentication Bypass in Mattermost Affects User Meeting and Post Management
CVE-2026-0998

4.3MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
16 February 2026

What is CVE-2026-0998?

A critical security issue in several versions of Mattermost and its Zoom plugin allows unauthorized users to access and control Zoom meetings. The vulnerability arises due to improper validation of user identity and post ownership in the /api/v1/askPMI API endpoint. This flaw enables attackers to start Zoom meetings impersonating any user, and manipulate or overwrite posts through direct API requests by providing coerced user IDs and post data. Organizations using affected versions are strongly encouraged to review the Mattermost security advisory and apply necessary patches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Mattermost 11.1.0 <= 11.1.2

Mattermost 10.11.0 <= 10.11.9

Mattermost 11.2.0 <= 11.2.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daw10
.