CVE-2026-22545
vulnerability analysis and mitigation

Overview

CVE-2026-22545 is an incorrect authorization vulnerability in Mattermost Server that allows an authenticated attacker to change an account's password without confirmation by falsely claiming a different authentication provider. It affects Mattermost versions 10.11.0 through 10.11.10 (inclusive). The vulnerability was published on March 16, 2026, and is tracked under Mattermost Advisory ID MMSA-2026-00583. It carries a CVSS v3.1 base score of 3.5 (Low) (Mattermost Security, Red Hat CVE).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization): Mattermost fails to validate a user's current authentication method when processing an account auth type switch request. An authenticated attacker can craft a request that falsely claims a different authentication provider, bypassing the confirmation step normally required for a password change. The attack vector is network-based, requires low privileges (an authenticated session), and requires some user interaction, limiting its scope. No public proof-of-concept code has been identified (Mattermost Security, ENISA EUVD).

Impact

Successful exploitation allows an authenticated attacker to perform unauthorized password changes on targeted accounts by abusing the auth provider switch endpoint without proper verification. This results in a low integrity impact — specifically, account integrity compromise that could facilitate account takeover if the attacker has knowledge of another user's account identifier. There is no confidentiality or availability impact associated with this vulnerability (Mattermost Security, ENISA EUVD).

Exploitation steps

  1. Authentication: Obtain valid credentials for any Mattermost account on an instance running versions 10.11.0–10.11.10.
  2. Identify target account: Determine the username or account identifier of the target user whose password is to be changed.
  3. Craft malicious auth-switch request: Send an API request to the Mattermost auth type switch endpoint, falsely specifying a different authentication provider (e.g., claiming the account uses LDAP or SAML when it does not).
  4. Bypass confirmation: Because the server fails to validate the user's actual current authentication method, the confirmation step for the password change is bypassed.
  5. Set new password: The attacker supplies a new password in the request, which is accepted and applied to the target account without proper authorization checks, potentially enabling account takeover (Mattermost Security, ENISA EUVD).

Indicators of compromise

  • Logs: Mattermost server logs showing auth type switch API calls (e.g., requests to /api/v4/users/{user_id}/auth) from users who do not normally use alternative authentication providers; password change events lacking a corresponding user-initiated confirmation flow.
  • Network: Unusual API requests targeting the auth type switch endpoint from authenticated sessions, particularly for accounts belonging to other users.
  • Behavioral: Multiple failed or successful password change events for accounts that were not initiated by the account owner; unexpected login activity following a password change event on an account.

Mitigation and workarounds

Mattermost has released version 10.11.11 which addresses this vulnerability. Organizations running any Mattermost Server version from 10.11.0 through 10.11.10 should upgrade to 10.11.11 or later immediately. As an interim measure, administrators should monitor access logs for suspicious auth type switch requests and review account activity for unauthorized password changes. No configuration-based workaround has been published (Mattermost Security, openSUSE Security).

Community reactions

Coverage of CVE-2026-22545 has been limited to standard vulnerability database aggregators and automated security feeds. A brief technical write-up was published at infinitsec.net describing the password change bypass via the auth switch endpoint. No significant vendor statements beyond the official Mattermost security advisory, nor notable researcher commentary or broad media coverage, have been identified (Mattermost Security).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management