
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-16049 is an authorization bypass vulnerability in the Mattermost GitLab plugin that allows authenticated attackers to inject bot-authored messages containing arbitrary URLs into channels they do not have access to. It affects Mattermost Plugins versions ≤11.8, ≤10.20.11, and ≤11.5.7, and was published on August 17, 2026 (Mattermost Advisory ID: MMSA-2026-00673). Fixed versions include 11.9.0, 10.11.21, and 11.7.6. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory).
The vulnerability is classified as CWE-862 (Missing Authorization). The Mattermost GitLab plugin fails to verify channel permissions when processing API requests that include a caller-supplied post_id parameter, and also fails to validate the web_url parameter against the configured GitLab instance. This allows an authenticated attacker to craft requests to the createIssue and attachCommentToIssue API endpoints, causing the bot to post messages with arbitrary URLs into channels the attacker does not have legitimate access to. No special privileges beyond a valid authenticated session are required, and exploitation requires no user interaction (GitHub Advisory).
Successful exploitation allows an authenticated attacker to inject bot-authored messages containing arbitrary URLs into restricted Mattermost channels, potentially enabling phishing attacks or distribution of malicious links to users in those channels. The confidentiality impact is rated low (partial information disclosure about channel existence/accessibility), while integrity and availability are unaffected according to the CVSS scoring. The scope is limited to the Mattermost instance and does not enable direct lateral movement or remote code execution (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.218% (13th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and NVD's SSVC assessment confirms no known exploitation (GitHub Advisory).
post_id of a post in a restricted channel the attacker does not have access to (e.g., via enumeration or prior knowledge).createIssue or attachCommentToIssue GitLab plugin API endpoint, supplying the target channel's post_id as a caller-controlled parameter.web_url parameter value that is not validated against the configured GitLab instance.createIssue or attachCommentToIssue endpoints from users who are not members of the target channel.post_id values in GitLab plugin API requests that reference posts in channels the requesting user does not belong to.Upgrade the Mattermost GitLab plugin to a version newer than 11.8; the fixed Mattermost server versions are 11.9.0, 10.11.21, and 11.7.6. The patch is available via the GitHub Advisory. As a workaround, administrators can disable the Mattermost GitLab plugin until the update can be applied, or implement network-level controls to restrict access to the affected API endpoints. Additionally, enforcing strict access controls and monitoring bot activity in restricted channels is recommended (GitHub Advisory, Mattermost Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."