CVE-2026-2299
Awaiting Analysis Awaiting Analysis - Queue
Mattermost Google Drive Plugin Channel Membership Validation Flaw

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: Mattermost, Inc.

Description
The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
mattermost google_drive_plugin to 1.1.0 (exc)
mattermost mattermost_google_drive_plugin to 1.1.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

The vulnerability allows authenticated users to share Google Drive files to unauthorized private channels and disclose private channel membership. This unauthorized disclosure of private information could potentially lead to non-compliance with data protection regulations such as GDPR and HIPAA, which require strict controls on access to personal and sensitive information.

Executive Summary

The vulnerability exists in the Mattermost Google Drive plugin before version 1.1.0. It occurs because the plugin fails to properly validate whether a user is a member of a channel when creating files. This flaw allows authenticated users who have connected their Google account to share Google Drive files to private channels they are not authorized to access. Additionally, it can disclose the membership of these private channels.

Impact Analysis

This vulnerability can lead to unauthorized disclosure of private channel membership and sharing of Google Drive files to private channels without proper authorization. As a result, sensitive information intended to be restricted within private channels could be exposed to unauthorized users, potentially compromising confidentiality and privacy.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-2299. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart