OAuth Deauthorization and Token Management Flaw in Mattermost
CVE-2026-16045

2.7LOW

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
17 August 2026

What is CVE-2026-16045?

Mattermost's failure to properly secure OAuth deauthorization and personal access token management endpoints leaves users exposed. This flaw allows OAuth applications with delegated user tokens to revoke authorizations or tokens across various integrations via account management endpoints. This oversight can lead to unauthorized access and potential compromise of user accounts, highlighting the critical need for users to update to secure versions of the application and review connected OAuth integrations.

Affected Version(s)

Mattermost 11.7.0 <= 11.7.6

Mattermost 10.11.0 <= 10.11.21

Mattermost 11.9.0

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

KennySki
.