news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-5139

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
5.4 Medium
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Risk score
43.2
Published
2026-06-22
Status
Published

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administrator authorization on the call within the command handler, which allows any authenticated user to overwrite the global default GitLab instance configuration via the slash command.. Mattermost Advisory ID: MMSA-2026-00644

Weaknesses

CWE-862

Coverage 1

Advisories and references