CVE-2026-27656
published 2026-03-25CVE-2026-27656: Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID…
PriorityP433medium6.1CVSS 3.1
AVNACLPRHUIRSUCHIHAN
EPSS
0.18%
7.8th percentile
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts via an overly permissive substring matching flaw in the user discovery flow.. Mattermost Advisory ID: MMSA-2026-00590
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 10.11.0-rc1 < 10.11.12 | 10.11.12 |
| github.com | mattermost_mattermost-server | >= 11.2.0-rc1 < 11.2.4 | 11.2.4 |
| github.com | mattermost_mattermost-server | >= 11.3.0-rc1 < 11.3.2 | 11.3.2 |
| github.com | mattermost_mattermost-server | >= 11.4.0-rc1 < 11.4.1 | 11.4.1 |
| github.com | mattermost_mattermost_server_v8 | >= 8.0.0-20260105080200-d27a2195068d < 8.0.0-20260217110922-b7d4a1f1f59b | 8.0.0-20260217110922-b7d4a1f1f59b |
| mattermost | mattermost | 10.11.0 – 10.11.11 | — |
| mattermost | mattermost | 11.2.0 – 11.2.3 | — |
| mattermost | mattermost | 11.3.0 – 11.3.1 | — |
| mattermost | mattermost | 11.4.0 – 11.4.0 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.12 | 10.11.12 |
| mattermost | mattermost_server | >= 11.2.0 < 11.2.4 | 11.2.4 |
| mattermost | mattermost_server | >= 11.3.0 < 11.3.2 | 11.3.2 |
| mattermost | mattermost_server | >= 11.4.0 < 11.4.1 | 11.4.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw
osv·2026-03-25
CVE-2026-27656 [MEDIUM] Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw
Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts via an overly permissive substring matching flaw in the user discovery flow. Mattermost Advisory ID: MMSA-2026-00590
GHSA
Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw
ghsa·2026-03-25
CVE-2026-27656 [MEDIUM] CWE-303 Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw
Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts via an overly permissive substring matching flaw in the user discovery flow. Mattermost Advisory ID: MMSA-2026-00590
No detection rules found.
No public exploits indexed.
2026-03-25
Published