← Back

CVE-2026-28732

nvd nist
Published: May 18, 2026Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: responsibledisclosure@mattermost.com (Secondary)

Description

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom slash commands via editing their own slash command trigger to an already-registered trigger through the command update API. Mattermost Advisory ID: MMSA-2026-00597

Affected (3)

1 product
Mattermost Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Mattermost
From 10.11.0 to 10.11.14
From 11.4.0 to 11.4.4
From 11.5.0 to 11.5.2

References (1)

Source: responsibledisclosure@mattermost.com
Vendor Advisory

Timeline

No history available yet.