OAuth Endpoint Vulnerability in Mattermost by Mattermost
CVE-2026-96259

5.5MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
22 September 2026

What is CVE-2026-96259?

Mattermost versions up to 11.9.1, including earlier intervals of 11.8.x, 11.7.x, and 11.10.x, are prone to a vulnerability that affects the OAuth endpoint. This weakness permits a System Administrator to force the server to execute requests to internal network locations, obtaining responses through configured OAuth tokens and userinfo endpoints. Organizations using these versions should review their configurations and apply the latest security updates to mitigate potential risks. For detailed information, refer to the Mattermost Advisory ID: MMSA-2026-00776.

Affected Version(s)

Mattermost 11.9.0 <= 11.9.1

Mattermost 11.8.0 <= 11.8.5

Mattermost 11.7.0 <= 11.7.10

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n1nj4sec
.