Vulnerability in Mattermost GitLab Plugin Affects Unauthorized Access and API Security
CVE-2026-16049
What is CVE-2026-16049?
The Mattermost GitLab plugin exhibits a security flaw that allows an authenticated user to bypass channel permissions when making API requests. Specifically, the plugin fails to adequately verify the permissions of the caller-supplied post_id and does not validate the web_url parameter against the configured GitLab instance. As a result, this vulnerability permits attackers with valid credentials to inject bot-generated messages containing arbitrary URLs into channels that should otherwise be inaccessible to them, potentially leading to unauthorized access and information dissemination. Administrators are advised to review the latest Mattermost security advisory and implement necessary updates to mitigate this risk.
Affected Version(s)
Mattermost 0 <= 10.20.11
Mattermost 0 <= 11.5.7
Mattermost 11.9.0