LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-2462

mattermost · mattermost server

Published
CVSS6.6
Severitymedium
WeaknessCWE-863
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Description

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528

References

← Back to the CVE Tracker

Our coverage of CVE-2026-2462

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-2462.