CVE Vulnerabilities

CVE-2026-2457

Origin Validation Error

Published: Mar 16, 2026 | Modified: Mar 18, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonating other users via crafted PUT requests to the post update API endpoint.. Mattermost Advisory ID: MMSA-2025-00569

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

NameVendorStart VersionEnd Version
Mattermost_serverMattermost10.11.0 (including)10.11.11 (excluding)
Mattermost_serverMattermost11.2.0 (including)11.2.3 (excluding)
Mattermost_serverMattermost11.3.0 (including)11.3.1 (excluding)

References