OAuth Token Scope Validation Flaw in Mattermost
CVE-2026-28735

5.4MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
22 May 2026

What is CVE-2026-28735?

Mattermost contains a vulnerability where the OAuth token scope is not properly validated during the callback process. This security flaw permits an authenticated user to gain unauthorized access to private repositories by simply altering the scope parameter within the GitHub authorization URL. It affects multiple versions of Mattermost, posing a serious risk to user privacy and data integrity. Admins are strongly advised to review the Mattermost security advisory for mitigation steps.

Affected Version(s)

Mattermost 11.6.0

Mattermost 11.5.0 <= 11.5.3

Mattermost 11.4.0 <= 11.4.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

eahmed
.