
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27769 is a missing authorization vulnerability in Mattermost Server affecting versions 10.11.0 through 10.11.12 (inclusive). The flaw allows a malicious remote server connected via the Connected Workspaces feature to manipulate the displayed status of local users through the Connected Workspaces API, without proper ownership validation. It was published on April 15, 2026, with the Mattermost Advisory ID MMSA-2026-00603. The vulnerability carries a CVSS v3.1 base score of 2.7 (Low) (Red Hat Bugzilla, GitHub Advisory).
The root cause is classified as CWE-862 (Missing Authorization): Mattermost fails to validate whether users are correctly owned by the corresponding Connected Workspace before allowing status modifications via the Connected Workspaces API. An attacker controlling a remote server that has an established Connected Workspaces connection can send crafted API requests to alter the displayed presence/availability status of arbitrary local users on the target Mattermost instance. Exploitation requires high privileges (control of a connected remote server) and network access, but no user interaction. No public proof-of-concept or technical write-up detailing specific API endpoints or payloads has been identified (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows a malicious remote server to falsify the displayed status (e.g., online, offline, away) of local users on the affected Mattermost instance. There is no confidentiality or availability impact; the effect is limited to low-severity integrity degradation. However, manipulated user status information could be leveraged for social engineering attacks — for example, making a user appear unavailable to redirect communications — or cause operational disruption by providing misleading presence data within the platform (GitHub Advisory, Red Hat Bugzilla).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.037% (11th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to already control a remote server with an established Connected Workspaces connection to the target, significantly limiting the attack surface (GitHub Advisory).
Mattermost has released a fix in version 10.11.13 (Go module patched version: 8.0.0-20260316060126-bc1a2b34b1f9); organizations running 10.11.0–10.11.12 should upgrade immediately. As an interim workaround, administrators should review and restrict Connected Workspaces integrations to only explicitly trusted remote servers, and monitor Connected Workspaces API activity for unauthorized user status modifications. Consult the official Mattermost security advisory MMSA-2026-00603 for additional guidance (Mattermost Security, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."