CVE-2026-27769
published 2026-04-15CVE-2026-27769: Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote…
PriorityP411low2.7CVSS 3.1
AVNACLPRHUINSUCNILAN
EPSS
0.17%
6.3th percentile
Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed status of local users via the Connected Workspaces API.. Mattermost Advisory ID: MMSA-2026-00603
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 8.0.0-20250721062209-4952acea88ce < 8.0.0-20260316060126-bc1a2b34b1f9 | 8.0.0-20260316060126-bc1a2b34b1f9 |
| mattermost | mattermost | 10.11.0 – 10.11.12 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.13 | 10.11.13 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mxxh-fmjq-j6x4: Mattermost versions 10
ghsa_unreviewed·2026-04-17
CVE-2026-27769 [LOW] CWE-862 GHSA-mxxh-fmjq-j6x4: Mattermost versions 10
Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed status of local users via the Connected Workspaces API.. Mattermost Advisory ID: MMSA-2026-00603
GHSA
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace
ghsa·2026-04-17
CVE-2026-27769 [LOW] CWE-862 Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace
Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed status of local users via the Connected Workspaces API. Mattermost Advisory ID: MMSA-2026-00603.
VulDB
Mattermost up to 10.11.12/11.4.x Conntexted Workspaces Feature authorization
vuldb·2026-04-15·CVSS 2.7
CVE-2026-27769 [LOW] Mattermost up to 10.11.12/11.4.x Conntexted Workspaces Feature authorization
A vulnerability described as problematic has been identified in Mattermost up to 10.11.12/11.4.x. This vulnerability affects unknown code of the component Conntexted Workspaces Feature. Executing a manipulation can lead to missing authorization.
This vulnerability is tracked as CVE-2026-27769. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-27769 mattermost: connected workspaces: malicious remote server can manipulate arbitrary user's status
bugzilla·2026-04-15·CVSS 2.7
CVE-2026-27769 [LOW] CVE-2026-27769 mattermost: connected workspaces: malicious remote server can manipulate arbitrary user's status
CVE-2026-27769 mattermost: connected workspaces: malicious remote server can manipulate arbitrary user's status
Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed status of local users via the Connected Workspaces API.. Mattermost Advisory ID: MMSA-2026-00603
Bugzilla
CVE-2026-27769 matterbridge: connected workspaces: malicious remote server can manipulate arbitrary user's status [fedora-all]
bugzilla·2026-04-15·CVSS 2.7
CVE-2026-27769 [LOW] CVE-2026-27769 matterbridge: connected workspaces: malicious remote server can manipulate arbitrary user's status [fedora-all]
CVE-2026-27769 matterbridge: connected workspaces: malicious remote server can manipulate arbitrary user's status [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-27769 matterbridge: connected workspaces: malicious remote server can manipulate arbitrary user's status [epel-all]
bugzilla·2026-04-15·CVSS 2.7
CVE-2026-27769 [LOW] CVE-2026-27769 matterbridge: connected workspaces: malicious remote server can manipulate arbitrary user's status [epel-all]
CVE-2026-27769 matterbridge: connected workspaces: malicious remote server can manipulate arbitrary user's status [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
2026-04-15
Published