CVE-2026-0998
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-0998 is a missing authorization vulnerability in Mattermost Server and the Mattermost Plugin Zoom that allows authenticated low-privileged users to start Zoom meetings as any user and overwrite arbitrary posts via the /api/v1/askPMI endpoint. It affects Mattermost Server versions 10.11.0–10.11.9, 11.1.0–11.1.2, and 11.2.0–11.2.1, as well as Mattermost Plugin Zoom versions ≤1.11.0. The vulnerability was published on February 16, 2026, with patches released shortly after. It carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly, Mattermost Security).

Technical details

The root cause is CWE-862 (Missing Authorization): the /api/v1/askPMI endpoint in the Mattermost Zoom plugin fails to validate that the requesting user's identity matches the user ID supplied in the API call, and does not verify post ownership before allowing modifications. An authenticated attacker with low privileges can craft direct API calls with manipulated user IDs and post data to trigger unauthorized actions on behalf of other users. No complex preconditions are required beyond having a valid authenticated session on the Mattermost instance. The Mattermost Advisory ID for this issue is MMSA-2025-00534 (Feedly).

Impact

Successful exploitation allows a low-privileged authenticated attacker to impersonate any user to initiate Zoom meetings on their behalf and overwrite arbitrary posts within the Mattermost system. The primary impact is to integrity (unauthorized post modification) and availability of communication workflows, with no direct confidentiality impact. These capabilities could be leveraged for social engineering, communication hijacking, or spreading misinformation by altering posts attributed to other users (Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability requires a valid authenticated session (low privilege), making it accessible to any registered Mattermost user on an affected instance. The EPSS score is approximately 0.026% (0.000260), indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog (Feedly).

Exploitation steps

  1. Authentication: Log in to a vulnerable Mattermost instance with any valid low-privileged user account.
  2. Identify target user: Enumerate or guess the user ID of the target user whose identity will be impersonated (e.g., via Mattermost's user directory or API).
  3. Craft malicious API request: Send a direct HTTP POST request to the /api/v1/askPMI endpoint, substituting the target user's ID in the request body or parameters instead of the authenticated user's own ID.
  4. Initiate unauthorized Zoom meeting: The endpoint, lacking proper identity validation, processes the request as if it originated from the target user, initiating a Zoom meeting invitation on their behalf.
  5. Overwrite arbitrary posts: Similarly, craft API calls with manipulated post data and target post IDs to overwrite existing posts authored by other users, bypassing post ownership checks (Feedly).

Indicators of compromise

  • Network: Unusual or repeated API calls to /api/v1/askPMI from a single user account, especially with varying user IDs in the request payload.
  • Logs: Mattermost server logs showing requests to the Zoom plugin endpoint where the authenticated user ID does not match the user ID present in the request body; multiple Zoom meeting initiation events attributed to users who did not initiate them.
  • Application: Unexpected modifications to posts authored by users other than the currently authenticated session user; Zoom meeting invitations sent from accounts that deny initiating them.

Mitigation and workarounds

Mattermost has released patched versions addressing this vulnerability. Administrators should update to the following versions or later: Mattermost Server 10.11.10+, 11.1.3+, or 11.2.2+, and Mattermost Plugin Zoom 1.11.1+. No configuration-based workaround is documented; upgrading is the recommended remediation. Patches are available via the Mattermost security updates page (Mattermost Security).

Community reactions

Coverage of CVE-2026-0998 has been limited to standard vulnerability aggregation sites and a brief technical post. InfinitSec published a post describing the vulnerability's impact on unauthorized meeting creation and post modification (InfinitSec). No significant vendor statements beyond the security advisory or notable researcher commentary have been identified.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management