Vulnerability GHSA-2g8v-grq3-hq2g

Medium Risk
MEDIUM RISK
CVSS Score: 5.4
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 months ago
June 22, 2026 at 03:30 PM UTC
Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler
v10.11.0+incompatible - v10.11.17+incompatible and v11.5.0+incompatible - v11.5.5+incompatible and v11.6.0+incompatible - v11.6.2+incompatible and v11.7.0+incompatible
v10.11.0+incompatible - v10.11.17+incompatible and v11.5.0+incompatible - v11.5.5+incompatible and v11.6.0+incompatible - v11.6.2+incompatible and v11.7.0+incompatible

Summary

Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler

Details

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler, which allows any authenticated user to overwrite the global default GitLab instance configuration via the {{/gitlab connect }} slash command.. Mattermost Advisory ID: MMSA-2026-00644

Timeline

Published
2 months ago
June 22, 2026 at 03:30 PM UTC
Last Modified
1 day ago
September 15, 2026 at 08:00 PM UTC