CVE-2026-2462
—CVSS 3.1
6.6 medium
EPSS
<1%p26
Published
()
Modified
Description
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528
- Vendors
- mattermost
- Products
- mattermost server
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.