← Back

CVE-2026-2462

nvd nist
Published: Mar 16, 2026Modified: Mar 18, 2026

JSON object

Loading...
6.6
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Exploitability: 2.3 / Impact: 3.7
Source: responsibledisclosure@mattermost.com (Secondary)

Description

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528

Affected (3)

1 product
Mattermost Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Mattermost
From 10.11.0 to 10.11.11
From 11.2.0 to 11.2.3
From 11.3.0 to 11.3.1

References (1)

Source: responsibledisclosure@mattermost.com
Vendor Advisory

Timeline

No history available yet.