OAuth Token Scope Validation Flaw in Mattermost
CVE-2026-28735
5.4MEDIUM
What is CVE-2026-28735?
Mattermost contains a vulnerability where the OAuth token scope is not properly validated during the callback process. This security flaw permits an authenticated user to gain unauthorized access to private repositories by simply altering the scope parameter within the GitHub authorization URL. It affects multiple versions of Mattermost, posing a serious risk to user privacy and data integrity. Admins are strongly advised to review the Mattermost security advisory for mitigation steps.
Affected Version(s)
Mattermost 11.6.0
Mattermost 11.5.0 <= 11.5.3
Mattermost 11.4.0 <= 11.4.4