CVE-2026-3117
Analyzed
Analyzed - Analysis Complete
Mattermost GitLab Plugin Command Execution Flaw
Publication date: 2026-05-18
Last updated on: 2026-05-29
Assigner: Mattermost, Inc.
Description
Description
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin which allows normal users to uninstall instances or setup webhook connections via the {{gitlab instance {option}}} or the {{/gitlab webhook {option}}} commands. Mattermost Advisory ID: MMSA-2026-00600
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mattermost | mattermost_server | From 10.13.0 (inc) to 10.13.11 (inc) |
| mattermost | mattermost_server | From 11.1.0 (inc) to 11.1.5 (inc) |
| mattermost | mattermost_server | From 11.3.0 (inc) to 11.3.4 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |