CVE-2026-16049
Mattermost Desktop App vulnerability analysis and mitigation

Overview

CVE-2026-16049 is an authorization bypass vulnerability in the Mattermost GitLab plugin that allows authenticated attackers to inject bot-authored messages containing arbitrary URLs into channels they do not have access to. It affects Mattermost Plugins versions ≤11.8, ≤10.20.11, and ≤11.5.7, and was published on August 17, 2026 (Mattermost Advisory ID: MMSA-2026-00673). Fixed versions include 11.9.0, 10.11.21, and 11.7.6. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization). The Mattermost GitLab plugin fails to verify channel permissions when processing API requests that include a caller-supplied post_id parameter, and also fails to validate the web_url parameter against the configured GitLab instance. This allows an authenticated attacker to craft requests to the createIssue and attachCommentToIssue API endpoints, causing the bot to post messages with arbitrary URLs into channels the attacker does not have legitimate access to. No special privileges beyond a valid authenticated session are required, and exploitation requires no user interaction (GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker to inject bot-authored messages containing arbitrary URLs into restricted Mattermost channels, potentially enabling phishing attacks or distribution of malicious links to users in those channels. The confidentiality impact is rated low (partial information disclosure about channel existence/accessibility), while integrity and availability are unaffected according to the CVSS scoring. The scope is limited to the Mattermost instance and does not enable direct lateral movement or remote code execution (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.218% (13th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and NVD's SSVC assessment confirms no known exploitation (GitHub Advisory).

Exploitation steps

  1. Authentication: Obtain valid credentials for the target Mattermost instance with the GitLab plugin enabled.
  2. Identify target channel: Determine the post_id of a post in a restricted channel the attacker does not have access to (e.g., via enumeration or prior knowledge).
  3. Craft malicious API request: Send a crafted HTTP request to the createIssue or attachCommentToIssue GitLab plugin API endpoint, supplying the target channel's post_id as a caller-controlled parameter.
  4. Inject arbitrary URL: Include a malicious or attacker-controlled web_url parameter value that is not validated against the configured GitLab instance.
  5. Bot message delivery: The plugin processes the request without verifying channel permissions, causing the GitLab bot to post a message containing the arbitrary URL into the restricted channel, potentially exposing users to phishing or malicious content (GitHub Advisory).

Indicators of compromise

  • Logs: Mattermost server logs showing API calls to the GitLab plugin's createIssue or attachCommentToIssue endpoints from users who are not members of the target channel.
  • Logs: Bot-authored messages appearing in restricted channels containing external or unexpected URLs not originating from the configured GitLab instance.
  • Network: Outbound requests from the Mattermost server to external URLs (not the configured GitLab instance) triggered by plugin API calls.
  • Application: Unusual post_id values in GitLab plugin API requests that reference posts in channels the requesting user does not belong to.

Mitigation and workarounds

Upgrade the Mattermost GitLab plugin to a version newer than 11.8; the fixed Mattermost server versions are 11.9.0, 10.11.21, and 11.7.6. The patch is available via the GitHub Advisory. As a workaround, administrators can disable the Mattermost GitLab plugin until the update can be applied, or implement network-level controls to restrict access to the affected API endpoints. Additionally, enforcing strict access controls and monitoring bot activity in restricted channels is recommended (GitHub Advisory, Mattermost Security).

Additional resources


SourceThis report was generated using AI

Related Mattermost Desktop App vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-9816HIGH8.3
  • Mattermost Desktop App logoMattermost Desktop App
  • mattermost-10.11
NoYesAug 17, 2026
CVE-2026-9859MEDIUM6.5
  • Mattermost Desktop App logoMattermost Desktop App
  • mattermost-10.11
NoYesAug 17, 2026
CVE-2026-16049MEDIUM4.3
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoNoAug 17, 2026
CVE-2026-9693LOW3.5
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesAug 17, 2026
CVE-2026-75587LOW3.3
  • Mattermost Desktop App logoMattermost Desktop App
  • cpe:2.3:a:mattermost:mattermost_desktop
NoYesAug 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management