CVE-2026-6334
published 2026-05-18CVE-2026-6334: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth authorization code redemption flow which…
PriorityP417low3.8CVSS 3.1
AVNACLPRHUINSUCLILAN
EPSS
0.12%
2.0th percentile
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth authorization code redemption flow which allows an authenticated OAuth client to redeem authorization codes issued to a different client via a crafted token exchange request.. Mattermost Advisory ID: MMSA-2026-00570
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 5.3.2-0.20260318173148-e9ae890a013b | 5.3.2-0.20260318173148-e9ae890a013b |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20260318173148-e9ae890a013b | 8.0.0-20260318173148-e9ae890a013b |
| github.com | mattermost_mattermost_server_v8 | >= 10.11.0 < 10.11.14 | 10.11.14 |
| github.com | mattermost_mattermost_server_v8 | >= 11.5.0 < 11.5.2 | 11.5.2 |
| mattermost | mattermost | 10.11.0 – 10.11.13 | — |
| mattermost | mattermost | 11.5.0 – 11.5.1 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.14 | 10.11.14 |
| mattermost | mattermost_server | >= 11.5.0 < 11.5.2 | 11.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jp3f-x449-4q75: Mattermost versions 11
ghsa_unreviewed·2026-05-18
CVE-2026-6334 [LOW] CWE-305 GHSA-jp3f-x449-4q75: Mattermost versions 11
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth authorization code redemption flow which allows an authenticated OAuth client to redeem authorization codes issued to a different client via a crafted token exchange request.. Mattermost Advisory ID: MMSA-2026-00570
VulDB
Mattermost up to 10.11.13/11.5.1 OAuth Authorization authentication bypass
vuldb·2026-05-18·CVSS 3.1
CVE-2026-6334 [LOW] Mattermost up to 10.11.13/11.5.1 OAuth Authorization authentication bypass
A vulnerability marked as problematic has been reported in Mattermost up to 10.11.13/11.5.1. This issue affects some unknown processing of the component OAuth Authorization. The manipulation leads to authentication bypass by primary weakness.
This vulnerability is referenced as CVE-2026-6334. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow
ghsa·2026-05-18
CVE-2026-6334 [LOW] CWE-305 Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow
Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth authorization code redemption flow which allows an authenticated OAuth client to redeem authorization codes issued to a different client via a crafted token exchange request.. Mattermost Advisory ID: MMSA-2026-00570
Citrix
Citrix Security Bulletin CTX111827
vendor_citrix·CVSS 6.8
CVE-2006-6334 [MEDIUM] Citrix Security Bulletin CTX111827
Citrix Security Bulletin CTX111827
CVE References: CVE-2006-6334, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-18
Published