cbcvebase.
CVE-2026-3590
published 2026-04-15

CVE-2026-3590: Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link…

medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid magic link to establish multiple independent authenticated sessions via concurrent requests.. Mattermost Advisory ID: MMSA-2026-00624

Affected

13 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 10.11.0-rc1 < 10.11.1310.11.13
github.commattermost_mattermost-server>= 11.3.0-rc1 < 11.3.311.3.3
github.commattermost_mattermost-server>= 11.4.0-rc1 < 11.4.311.4.3
github.commattermost_mattermost-server>= 11.5.0-rc1 < 11.5.011.5.0
github.commattermost_mattermost_server_v8>= 8.0.0-20250721062209-4952acea88ce < 8.0.0-20250723052842-4cb8d89403328.0.0-20250723052842-4cb8d8940332
mattermostmattermost10.11.0 – 10.11.12
mattermostmattermost11.3.0 – 11.3.2
mattermostmattermost11.4.0 – 11.4.2
mattermostmattermost11.5.0 – 11.5.0
mattermostmattermost_server>= 10.11.0 < 10.11.1310.11.13
mattermostmattermost_server>= 11.3.0 < 11.3.311.3.3
mattermostmattermost_server>= 11.4.0 < 11.4.311.4.3
mattermostmattermost_server>= 11.5.0 < 11.5.111.5.1