CVE-2026-27656

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts via an overly permissive substring matching flaw in the user discovery flow.. Mattermost Advisory ID: MMSA-2026-00590
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

History

26 Mar 2026, 18:51

Type Values Removed Values Added
Summary
  • (es) Las versiones de Mattermost 11.4.x &lt;= 11.4.0, 11.3.x &lt;= 11.3.1, 11.2.x &lt;= 11.2.3, 10.11.x &lt;= 10.11.11 no validan correctamente la identidad del usuario en la lógica de comparación OpenID {{IsSameUser()}}, lo que permite a un atacante tomar el control de cuentas de usuario arbitrarias a través de un fallo de coincidencia de subcadenas excesivamente permisivo en el flujo de descubrimiento de usuarios. ID de aviso de Mattermost: MMSA-2026-00590
First Time Mattermost
Mattermost mattermost Server
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

25 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 17:16

Updated : 2026-03-26 18:51


NVD link : CVE-2026-27656

Mitre link : CVE-2026-27656

CVE.ORG link : CVE-2026-27656


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-303

Incorrect Implementation of Authentication Algorithm