CVE-2026-2299
Analyzed
Analyzed - Analysis Complete
Mattermost Google Drive Plugin Channel Membership Validation Flaw
Vulnerability report for CVE-2026-2299, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-06-25
Last updated on: 2026-08-11
Assigner: Mattermost, Inc.
Description
Description
The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mattermost | google_drive | to 1.1.0 (exc) |
| mattermost | google_drive | 1.1.0 |
| mattermost | google_drive | 1.1.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |