Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/mattermost/mattermost-server
  4. ›
  5. CVE-2026-4273

CVE-2026-4273: Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation

May 18, 2026 (updated June 1, 2026)

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation which allows an authenticated attacker to bypass token rotation and reuse the original invite token via sending a crafted invite confirmation with a RefreshedToken matching the original token. Mattermost Advisory ID: MMSA-2026-00575

References

  • github.com/advisories/GHSA-hqpj-f3jh-29vx
  • github.com/mattermost/mattermost/commit/742e0be9507454a7e662668e1d9ec1b94b636e9b
  • mattermost.com/security-updates
  • nvd.nist.gov/vuln/detail/CVE-2026-4273

Code Behaviors & Features

Detect and mitigate CVE-2026-4273 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 5.3.2-0.20260313190740-742e0be95074

Fixed versions

  • 5.3.2-0.20260313190740-742e0be95074

Solution

Upgrade to version 5.3.2-0.20260313190740-742e0be95074 or above.

Impact 3.7 LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-863: Incorrect Authorization

Source file

go/github.com/mattermost/mattermost-server/CVE-2026-4273.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:23:28 +0000.