Feed/CVE-2026-28735
CVE-2026-28735MEDIUMCVSS 5.4

Mattermost allows authenticated users to gain access to private repositories

Published May 26, 2026·Updated Jun 29, 2026

NVD Description

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying the scope parameter in the GitHub authorization URL. Mattermost Advisory ID: MMSA-2026-00628

Affected Packages (2)

github.com/mattermost/mattermost-plugin-githubGO
Fixed in 1.0.1-0.20260318132218-6e6b740c4852
github.com/mattermost/mattermost-serverGO
Fixed in 11.6.1

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free