ZeroHour

CVE-2026-2462

CVSS 3.1
6.6 medium
EPSS
<1%p26
Published
()
Modified
Description

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528

Vendors
mattermost
Products
mattermost server
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.