Authorization Flaw in Mattermost Google Drive Plugin
CVE-2026-2299

4.2MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
25 June 2026

What is CVE-2026-2299?

The Mattermost Google Drive plugin prior to version 1.1.0 contains a security flaw that fails to properly validate channel membership during the file creation process. This allows authenticated users with a connected Google account to share files from Google Drive into private channels unlawfully, potentially disclosing confidential channel membership information to unauthorized users. To mitigate this risk, it’s essential to upgrade to the latest version.

Affected Version(s)

Mattermost Google Drive Plugin 0 <= 1.0.0

Mattermost Google Drive Plugin 1.1.0

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lorenzo Gallegos
.