CVE-2026-22880
published 2026-05-21CVE-2026-22880: Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which…
PriorityP432medium6.1CVSS 3.1
AVNACHPRNUIRSCCHINAN
EPSS
0.12%
1.9th percentile
Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credentials for a legitimate Mattermost server via relaying the SSO code exchange flow through the mobile application. Mattermost Advisory ID: MMSA-2025-00564
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mattermost | mattermost | <= 2.0.37 | — |
| mattermost | mattermost_mobile | < 2.37.1 | 2.37.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j628-rc2h-qj7g: Mattermost Mobile Apps versions <=2
ghsa_unreviewed·2026-05-21
CVE-2026-22880 [MEDIUM] CWE-352 GHSA-j628-rc2h-qj7g: Mattermost Mobile Apps versions <=2
Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credentials for a legitimate Mattermost server via relaying the SSO code exchange flow through the mobile application. Mattermost Advisory ID: MMSA-2025-00564
VulDB
Mattermost prior 11.5.0 cross-site request forgery
vuldb·2026-05-21·CVSS 6.1
CVE-2026-22880 [MEDIUM] Mattermost prior 11.5.0 cross-site request forgery
A vulnerability labeled as problematic has been found in Mattermost. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery.
This vulnerability is registered as CVE-2026-22880. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-21
Published