Vulnerability GO-2026-6279
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 month ago
August 25, 2026 at 07:43 PM UTC
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server
v10.11.0+incompatible - v10.11.16+incompatible
v10.11.0+incompatible - v10.11.16+incompatible
Summary
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server
Details
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server
References
- ADVISORY — github.com
- ADVISORY — nvd.nist.gov
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — mattermost.com
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
3 hours ago
Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler in github.com/mattermost/mattermost-server
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6480
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6480
Unknown
3 hours ago
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint in github.com/mattermost/mattermost-server
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6481
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6481
Unknown
3 hours ago
Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation in github.com/mattermost/mattermost-server
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6482
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6482
Unknown
3 hours ago
Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret in github.com/mattermost/mattermost-server
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6483
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6483
Unknown
3 hours ago
Mattermost doesn't validate channel ownership of an existing subscription before applying edits in github.com/mattermost/mattermost-server
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6484
v10.11.0+incompatible - v10.11.17+incompatible GO-2026-6484
Impacted packages
Timeline
Published
1 month ago
August 25, 2026 at 07:43 PM UTC
Last Modified
1 month ago
August 26, 2026 at 01:13 AM UTC