
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0998 is a missing authorization vulnerability in Mattermost Server and the Mattermost Plugin Zoom that allows authenticated low-privileged users to start Zoom meetings as any user and overwrite arbitrary posts via the /api/v1/askPMI endpoint. It affects Mattermost Server versions 10.11.0–10.11.9, 11.1.0–11.1.2, and 11.2.0–11.2.1, as well as Mattermost Plugin Zoom versions ≤1.11.0. The vulnerability was published on February 16, 2026, with patches released shortly after. It carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly, Mattermost Security).
The root cause is CWE-862 (Missing Authorization): the /api/v1/askPMI endpoint in the Mattermost Zoom plugin fails to validate that the requesting user's identity matches the user ID supplied in the API call, and does not verify post ownership before allowing modifications. An authenticated attacker with low privileges can craft direct API calls with manipulated user IDs and post data to trigger unauthorized actions on behalf of other users. No complex preconditions are required beyond having a valid authenticated session on the Mattermost instance. The Mattermost Advisory ID for this issue is MMSA-2025-00534 (Feedly).
Successful exploitation allows a low-privileged authenticated attacker to impersonate any user to initiate Zoom meetings on their behalf and overwrite arbitrary posts within the Mattermost system. The primary impact is to integrity (unauthorized post modification) and availability of communication workflows, with no direct confidentiality impact. These capabilities could be leveraged for social engineering, communication hijacking, or spreading misinformation by altering posts attributed to other users (Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability requires a valid authenticated session (low privilege), making it accessible to any registered Mattermost user on an affected instance. The EPSS score is approximately 0.026% (0.000260), indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog (Feedly).
/api/v1/askPMI endpoint, substituting the target user's ID in the request body or parameters instead of the authenticated user's own ID./api/v1/askPMI from a single user account, especially with varying user IDs in the request payload.Mattermost has released patched versions addressing this vulnerability. Administrators should update to the following versions or later: Mattermost Server 10.11.10+, 11.1.3+, or 11.2.2+, and Mattermost Plugin Zoom 1.11.1+. No configuration-based workaround is documented; upgrading is the recommended remediation. Patches are available via the Mattermost security updates page (Mattermost Security).
Coverage of CVE-2026-0998 has been limited to standard vulnerability aggregation sites and a brief technical post. InfinitSec published a post describing the vulnerability's impact on unauthorized meeting creation and post modification (InfinitSec). No significant vendor statements beyond the security advisory or notable researcher commentary have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."