Executive brief
Mattermost Mobile Apps, used for secure team communication, contain a vulnerability in how they handle Single Sign-On (SSO) logins. An attacker who convinces a user to connect to a malicious Mattermost server could intercept the user's login credentials for their legitimate corporate server. This could lead to unauthorized access to sensitive company communications and data.
Technical details
A vulnerability in Mattermost Mobile Apps (versions up to 2.37 and various 10.x/11.x branches) stems from improper validation of the SSO authentication callback origin. The flaw is categorized as a Cross-Site Request Forgery (CSRF) variant where the application fails to verify the source of the authentication code exchange. An attacker operating a rogue Mattermost server can relay the SSO code exchange flow through the mobile application to capture credentials intended for a legitimate server. Exploitation requires network reachability and user interaction (connecting to the malicious server), and it results in high confidentiality impact as the attacker can gain unauthorized access to the user's legitimate account.
Affected products
- Mattermost Mobile Apps <=2.37, 11.4, 2.0.37, 11.0.4, 11.1.3, 11.3.2, 10.11.11.0
Timeline
- 2026-05-21: disclosed: NVD publication date
- 2026-05-21: advisory: Mattermost Advisory MMSA-2025-00564 published