OAuth Endpoint Vulnerability in Mattermost by Mattermost
CVE-2026-96259
5.5MEDIUM
What is CVE-2026-96259?
Mattermost versions up to 11.9.1, including earlier intervals of 11.8.x, 11.7.x, and 11.10.x, are prone to a vulnerability that affects the OAuth endpoint. This weakness permits a System Administrator to force the server to execute requests to internal network locations, obtaining responses through configured OAuth tokens and userinfo endpoints. Organizations using these versions should review their configurations and apply the latest security updates to mitigate potential risks. For detailed information, refer to the Mattermost Advisory ID: MMSA-2026-00776.
Affected Version(s)
Mattermost 11.9.0 <= 11.9.1
Mattermost 11.8.0 <= 11.8.5
Mattermost 11.7.0 <= 11.7.10