cbcvebase.
CVE-2026-27769
published 2026-04-15

CVE-2026-27769: Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote…

PriorityP411low2.7CVSS 3.1
AVNACLPRHUINSUCNILAN
EPSS
0.17%
6.3th percentile
Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed status of local users via the Connected Workspaces API.. Mattermost Advisory ID: MMSA-2026-00603

Affected

3 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 8.0.0-20250721062209-4952acea88ce < 8.0.0-20260316060126-bc1a2b34b1f98.0.0-20260316060126-bc1a2b34b1f9
mattermostmattermost10.11.0 – 10.11.12
mattermostmattermost_server>= 10.11.0 < 10.11.1310.11.13
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.