Vulnerability in Mattermost GitLab Plugin Affects Unauthorized Access and API Security
CVE-2026-16049

3.9LOW

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
17 August 2026

What is CVE-2026-16049?

The Mattermost GitLab plugin exhibits a security flaw that allows an authenticated user to bypass channel permissions when making API requests. Specifically, the plugin fails to adequately verify the permissions of the caller-supplied post_id and does not validate the web_url parameter against the configured GitLab instance. As a result, this vulnerability permits attackers with valid credentials to inject bot-generated messages containing arbitrary URLs into channels that should otherwise be inaccessible to them, potentially leading to unauthorized access and information dissemination. Administrators are advised to review the latest Mattermost security advisory and implement necessary updates to mitigate this risk.

Affected Version(s)

Mattermost 0 <= 10.20.11

Mattermost 0 <= 11.5.7

Mattermost 11.9.0

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MindFlare007
.