CVE-2026-22880

Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credentials for a legitimate Mattermost server via relaying the SSO code exchange flow through the mobile application. Mattermost Advisory ID: MMSA-2025-00564
References
Configurations

No configuration.

History

23 Jul 2026, 16:10

Type Values Removed Values Added
Summary
  • (es) Las versiones de las aplicaciones móviles de Mattermost <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 no validan correctamente el origen de la devolución de llamada de autenticación SSO, lo que permite a un atacante que controla un servidor Mattermost malicioso robar las credenciales de usuario de un servidor Mattermost legítimo mediante la retransmisión del flujo de intercambio de código SSO a través de la aplicación móvil. ID de aviso de Mattermost: MMSA-2025-00564

21 May 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-21 09:16

Updated : 2026-07-23 16:10


NVD link : CVE-2026-22880

Mitre link : CVE-2026-22880

CVE.ORG link : CVE-2026-22880


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)