Vulnerabilities
- CVSS
- 5.4 Medium
- Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L- Risk score
- 43.2
- Published
- 2026-06-22
- Status
- Published
Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administrator authorization on the call within the command handler, which allows any authenticated user to overwrite the global default GitLab instance configuration via the slash command.. Mattermost Advisory ID: MMSA-2026-00644
Coverage 1
vulnerability
Multiple vulnerabilities have been discovered in Mattermost products, allowing an attacker to bypass security policies and potentially lead to an unspecified security issue. These vulnerabilities affect various versions…
Advisories and references