CVE-2026-28732
published 2026-05-18CVE-2026-28732: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which…
PriorityP424medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.15%
4.9th percentile
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom slash commands via editing their own slash command trigger to an already-registered trigger through the command update API. Mattermost Advisory ID: MMSA-2026-00597
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 5.3.2-0.20260306123948-f5fe8ded6b63 | 5.3.2-0.20260306123948-f5fe8ded6b63 |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20260306123948-f5fe8ded6b63 | 8.0.0-20260306123948-f5fe8ded6b63 |
| github.com | mattermost_mattermost_server_v8 | >= 10.11.0 < 10.11.14 | 10.11.14 |
| github.com | mattermost_mattermost_server_v8 | >= 11.4.0 < 11.4.4 | 11.4.4 |
| github.com | mattermost_mattermost_server_v8 | >= 11.5.0 < 11.5.2 | 11.5.2 |
| mattermost | mattermost | 10.11.0 – 10.11.13 | — |
| mattermost | mattermost | 11.4.0 – 11.4.3 | — |
| mattermost | mattermost | 11.5.0 – 11.5.1 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.14 | 10.11.14 |
| mattermost | mattermost_server | >= 11.4.0 < 11.4.4 | 11.4.4 |
| mattermost | mattermost_server | >= 11.5.0 < 11.5.2 | 11.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wvcv-9xpm-7mqc: Mattermost versions 11
ghsa_unreviewed·2026-05-18
CVE-2026-28732 [MEDIUM] CWE-863 GHSA-wvcv-9xpm-7mqc: Mattermost versions 11
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom slash commands via editing their own slash command trigger to an already-registered trigger through the command update API. Mattermost Advisory ID: MMSA-2026-00597
GHSA
Mattermost doesn't enforce slash command trigger-word uniqueness during command updates
ghsa·2026-05-18
CVE-2026-28732 [MEDIUM] CWE-863 Mattermost doesn't enforce slash command trigger-word uniqueness during command updates
Mattermost doesn't enforce slash command trigger-word uniqueness during command updates
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom slash commands via editing their own slash command trigger to an already-registered trigger through the command update API. Mattermost Advisory ID: MMSA-2026-00597
VulDB
Mattermost up to 10.11.13/11.4.3/11.5.1 Command Update API authorization (EUVD-2026-30760)
vuldb·2026-05-18·CVSS 4.3
CVE-2026-28732 [MEDIUM] Mattermost up to 10.11.13/11.4.3/11.5.1 Command Update API authorization (EUVD-2026-30760)
A vulnerability was found in Mattermost up to 10.11.13/11.4.3/11.5.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Command Update API. The manipulation results in incorrect authorization.
This vulnerability is reported as CVE-2026-28732. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-18
Published