CVE-2026-3117
published 2026-05-18CVE-2026-3117: Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin which allows…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.23%
13.8th percentile
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin which allows normal users to uninstall instances or setup webhook connections via the {{gitlab instance {option}}} or the {{/gitlab webhook {option}}} commands. Mattermost Advisory ID: MMSA-2026-00600
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | >= 0 < 6.1.162 | 6.1.162 |
| linux | linux_kernel | >= 6.13.0 < 6.18.7 | 6.18.7 |
| linux | linux_kernel | >= 6.2.0 < 6.6.122 | 6.6.122 |
| linux | linux_kernel | >= 6.7.0 < 6.12.67 | 6.12.67 |
| mattermost | mattermost | <= 11.1.5 | — |
| mattermost | mattermost_server | 10.13.0 – 10.13.11 | — |
| mattermost | mattermost_server | 11.1.0 – 11.1.5 | — |
| mattermost | mattermost_server | 11.3.0 – 11.3.4 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5gjv-5xhr-vc35: Mattermost Plugins versions <=11
ghsa_unreviewed·2026-05-18
CVE-2026-3117 [MEDIUM] CWE-862 GHSA-5gjv-5xhr-vc35: Mattermost Plugins versions <=11
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin which allows normal users to uninstall instances or setup webhook connections via the {{gitlab instance {option}}} or the {{/gitlab webhook {option}}} commands. Mattermost Advisory ID: MMSA-2026-00600
VulDB
Mattermost up to 11.5.1 Gitlab Plugin authorization
vuldb·2026-05-18·CVSS 6.5
CVE-2026-3117 [MEDIUM] Mattermost up to 11.5.1 Gitlab Plugin authorization
A vulnerability described as problematic has been identified in Mattermost up to 11.5.1. This affects an unknown function of the component Gitlab Plugin. Such manipulation leads to missing authorization.
This vulnerability is referenced as CVE-2026-3117. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
OSV
ipv6: Fix use-after-free in inet6_addr_del().
osv·2026-01-25·CVSS 7.8
CVE-2026-23010 ipv6: Fix use-after-free in inet6_addr_del().
ipv6: Fix use-after-free in inet6_addr_del().
In the Linux kernel, the following vulnerability has been resolved:
ipv6: Fix use-after-free in inet6_addr_del().
syzbot reported use-after-free of inet6_ifaddr in
inet6_addr_del(). [0]
The cited commit accidentally moved ipv6_del_addr() for
mngtmpaddr before reading its ifp->flags for temporary
addresses in inet6_addr_del().
Let's move ipv6_del_addr() down to fix the UAF.
[0]:
BUG: KASAN: slab-use-after-free in inet6_addr_del.constprop.0+0x67a/0x6b0 net/ipv6/addrconf.c:3117
Read of size 4 at addr ffff88807b89c86c by task syz.3.1618/9593
CPU: 0 UID: 0 PID: 9593 Comm: syz.3.1618 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025
Call Trace:
__dump_stack lib/dum
Red Hat
kernel: Linux kernel: Use-after-free in IPv6 address deletion may lead to a denial of service
vendor_redhat·2026-01-25·CVSS 7.8
CVE-2026-23010 [HIGH] CWE-825 kernel: Linux kernel: Use-after-free in IPv6 address deletion may lead to a denial of service
kernel: Linux kernel: Use-after-free in IPv6 address deletion may lead to a denial of service
In the Linux kernel, the following vulnerability has been resolved:
ipv6: Fix use-after-free in inet6_addr_del().
syzbot reported use-after-free of inet6_ifaddr in
inet6_addr_del(). [0]
The cited commit accidentally moved ipv6_del_addr() for
mngtmpaddr before reading its ifp->flags for temporary
addresses in inet6_addr_del().
Let's move ipv6_del_addr() down to fix the UAF.
[0]:
BUG: KASAN: slab-use-after-free in inet6_addr_del.constprop.0+0x67a/0x6b0 net/ipv6/addrconf.c:3117
Read of size 4 at addr ffff88807b89c86c by task syz.3.1618/9593
CPU: 0 UID: 0 PID: 9593 Comm: syz.3.1618 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-18
Published