
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22545 is an incorrect authorization vulnerability in Mattermost Server that allows an authenticated attacker to change an account's password without confirmation by falsely claiming a different authentication provider. It affects Mattermost versions 10.11.0 through 10.11.10 (inclusive). The vulnerability was published on March 16, 2026, and is tracked under Mattermost Advisory ID MMSA-2026-00583. It carries a CVSS v3.1 base score of 3.5 (Low) (Mattermost Security, Red Hat CVE).
The root cause is classified as CWE-863 (Incorrect Authorization): Mattermost fails to validate a user's current authentication method when processing an account auth type switch request. An authenticated attacker can craft a request that falsely claims a different authentication provider, bypassing the confirmation step normally required for a password change. The attack vector is network-based, requires low privileges (an authenticated session), and requires some user interaction, limiting its scope. No public proof-of-concept code has been identified (Mattermost Security, ENISA EUVD).
Successful exploitation allows an authenticated attacker to perform unauthorized password changes on targeted accounts by abusing the auth provider switch endpoint without proper verification. This results in a low integrity impact — specifically, account integrity compromise that could facilitate account takeover if the attacker has knowledge of another user's account identifier. There is no confidentiality or availability impact associated with this vulnerability (Mattermost Security, ENISA EUVD).
/api/v4/users/{user_id}/auth) from users who do not normally use alternative authentication providers; password change events lacking a corresponding user-initiated confirmation flow.Mattermost has released version 10.11.11 which addresses this vulnerability. Organizations running any Mattermost Server version from 10.11.0 through 10.11.10 should upgrade to 10.11.11 or later immediately. As an interim measure, administrators should monitor access logs for suspicious auth type switch requests and review account activity for unauthorized password changes. No configuration-based workaround has been published (Mattermost Security, openSUSE Security).
Coverage of CVE-2026-22545 has been limited to standard vulnerability database aggregators and automated security feeds. A brief technical write-up was published at infinitsec.net describing the password change bypass via the auth switch endpoint. No significant vendor statements beyond the official Mattermost security advisory, nor notable researcher commentary or broad media coverage, have been identified (Mattermost Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."