Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-03-16 14:19
Updated : 2026-03-18 18:31
NVD link : CVE-2026-2462
Mitre link : CVE-2026-2462
CVE.ORG link : CVE-2026-2462
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-863
Incorrect Authorization
