Vulnerability GHSA-jqgv-39mg-7c2r

Medium Risk
MEDIUM RISK
CVSS Score: 6.4
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 months ago
June 22, 2026 at 03:30 PM UTC
Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret
v10.11.0+incompatible - v10.11.17+incompatible and v11.5.0+incompatible - v11.5.5+incompatible and v11.6.0+incompatible - v11.6.2+incompatible and v11.7.0+incompatible
v10.11.0+incompatible - v10.11.17+incompatible and v11.5.0+incompatible - v11.5.5+incompatible and v11.6.0+incompatible - v11.6.2+incompatible and v11.7.0+incompatible

Summary

Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret

Details

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret and disrupt the Jira integration via POST to /ac/installed during the pending-install window.. Mattermost Advisory ID: MMSA-2026-00654

Timeline

Published
2 months ago
June 22, 2026 at 03:30 PM UTC
Last Modified
1 day ago
September 15, 2026 at 08:00 PM UTC