
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2457 is a post metadata spoofing vulnerability in Mattermost Server that allows authenticated attackers to impersonate other users by spoofing permalink embeds. The flaw affects Mattermost Server versions 10.11.x ≤ 10.11.10, 11.2.x ≤ 11.2.2, and 11.3.x ≤ 11.3.0. It was published on March 16, 2026, and is tracked under Mattermost Advisory ID MMSA-2025-00569. It carries a CVSS v3.1 base score of 4.3 (Medium) (Mattermost Security).
The root cause is insufficient sanitization of client-supplied post metadata in the post update API endpoint, classified as CWE-346 (Origin Validation Error). An authenticated attacker can craft malicious PUT requests to the post update API endpoint, injecting arbitrary permalink embed metadata that the server accepts without proper validation of the claimed origin or author identity. This allows the attacker to make posts appear as though they originate from or embed content attributed to other users. No special privileges beyond a valid authenticated session are required, and no user interaction is needed to trigger the spoofed display (Mattermost Security).
Successful exploitation allows an authenticated attacker to spoof permalink embeds within Mattermost channels, making messages appear to originate from or reference content attributed to other users. The primary impact is on integrity (CVSS integrity impact: Low), with no direct confidentiality or availability impact. In practice, this could enable social engineering attacks, phishing within trusted workspaces, unauthorized impersonation of colleagues or administrators, and erosion of trust in internal communications (Mattermost Security).
PUT /api/v4/posts/{post_id}) with a crafted JSON body that includes manipulated metadata fields — specifically, permalink embed data falsely attributing the embed to another user or referencing content from another user's post./api/v4/posts/{post_id} from a user account where the post metadata fields (e.g., embeds, permalink) reference content or users inconsistent with the requesting user's identity.Mattermost has released patched versions addressing this vulnerability. Users should upgrade to 10.11.11 or later (for the 10.11.x branch), 11.2.3 or later (for the 11.2.x branch), or 11.3.1 or later (for the 11.3.x branch). No official configuration-based workaround is available; upgrading is the recommended remediation. As an interim measure, administrators can restrict API access to the post update endpoint to trusted IP ranges and monitor PUT requests to /api/v4/posts/ for anomalous metadata patterns (Mattermost Security).
The vulnerability received routine coverage from automated CVE tracking services and security feeds shortly after disclosure on March 16, 2026, including mentions on CVE.org, VulnDB, and LinuxSecurity.com. An openSUSE security announcement was also issued referencing the vulnerability. No notable independent researcher commentary or significant social media discussion has been identified beyond standard CVE aggregation (Mattermost Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."