Token Mismanagement in Mattermost Reveals Session Hijacking Risk
CVE-2026-3590
6.5MEDIUM
What is CVE-2026-3590?
Certain versions of Mattermost are vulnerable due to improper enforcement of single-use consumption of guest magic link tokens. This flaw allows an attacker with access to a valid magic link to create multiple authenticated sessions concurrently, compromising account security and potentially leading to unauthorized access to user data.
Affected Version(s)
Mattermost 10.11.0 <= 10.11.12
Mattermost 11.5.0
Mattermost 11.4.0 <= 11.4.2