cbcvebase.
CVE-2026-0998
published 2026-02-16

CVE-2026-0998: Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post…

medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post ownership in the {{/api/v1/askPMI}} endpoint which allows unauthorized users to start Zoom meetings as any user and overwrite arbitrary posts via direct API calls with manipulated user IDs and post data.. Mattermost Advisory ID: MMSA-2025-00534

Affected

8 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-plugin-zoom>= 0 < 1.12.01.12.0
mattermostmattermost10.11.0 – 10.11.9
mattermostmattermost11.1.0 – 11.1.2
mattermostmattermost11.2.0 – 11.2.1
mattermostmattermost_server>= 10.11.0 < 10.11.1010.11.10
mattermostmattermost_server>= 11.1.0 < 11.1.311.1.3
mattermostmattermost_server>= 11.2.0 < 11.2.211.2.2
mattermostzoom<= 1.11.0