Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-27769
vulnerability analysis and mitigation

Overview

CVE-2026-27769 is a missing authorization vulnerability in Mattermost Server affecting versions 10.11.0 through 10.11.12 (inclusive). The flaw allows a malicious remote server connected via the Connected Workspaces feature to manipulate the displayed status of local users through the Connected Workspaces API, without proper ownership validation. It was published on April 15, 2026, with the Mattermost Advisory ID MMSA-2026-00603. The vulnerability carries a CVSS v3.1 base score of 2.7 (Low) (Red Hat Bugzilla, GitHub Advisory).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): Mattermost fails to validate whether users are correctly owned by the corresponding Connected Workspace before allowing status modifications via the Connected Workspaces API. An attacker controlling a remote server that has an established Connected Workspaces connection can send crafted API requests to alter the displayed presence/availability status of arbitrary local users on the target Mattermost instance. Exploitation requires high privileges (control of a connected remote server) and network access, but no user interaction. No public proof-of-concept or technical write-up detailing specific API endpoints or payloads has been identified (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows a malicious remote server to falsify the displayed status (e.g., online, offline, away) of local users on the affected Mattermost instance. There is no confidentiality or availability impact; the effect is limited to low-severity integrity degradation. However, manipulated user status information could be leveraged for social engineering attacks — for example, making a user appear unavailable to redirect communications — or cause operational disruption by providing misleading presence data within the platform (GitHub Advisory, Red Hat Bugzilla).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.037% (11th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to already control a remote server with an established Connected Workspaces connection to the target, significantly limiting the attack surface (GitHub Advisory).

Exploitation steps

  1. Establish a Connected Workspaces connection: The attacker must control a remote Mattermost server that has been granted a Connected Workspaces connection to the target Mattermost instance (requires prior administrative approval or compromise of a connected server).
  2. Identify target users: Enumerate local users on the target Mattermost instance accessible via the Connected Workspaces API.
  3. Send crafted API requests: Issue API calls through the Connected Workspaces API to modify the displayed status of target local users, exploiting the missing ownership validation check.
  4. Achieve status manipulation: The target instance accepts the status change without verifying that the users belong to the requesting workspace, resulting in falsified presence information visible to other users on the platform (GitHub Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Logs: Unexpected or anomalous user status change events in Mattermost server logs originating from a Connected Workspaces remote server, particularly for users who did not initiate a status change.
  • Network: Unusual volume of Connected Workspaces API calls from a remote server, especially targeting multiple local users in rapid succession.
  • Application: User-reported discrepancies between their actual status and what is displayed to colleagues, particularly when the affected users have not changed their own status.

Mitigation and workarounds

Mattermost has released a fix in version 10.11.13 (Go module patched version: 8.0.0-20260316060126-bc1a2b34b1f9); organizations running 10.11.0–10.11.12 should upgrade immediately. As an interim workaround, administrators should review and restrict Connected Workspaces integrations to only explicitly trusted remote servers, and monitor Connected Workspaces API activity for unauthorized user status modifications. Consult the official Mattermost security advisory MMSA-2026-00603 for additional guidance (Mattermost Security, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management