Junglewise Threat Intelligence

CVE-2026-27656: GO-2026-5360 - Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/matt

CVE-2026-27656 · Severity: low · CVSS 3.1 · Published 2026-06-25

Technologies: github.com/mattermost/mattermost-server/v5 (Go), github.com/mattermost/mattermost-server/v6 (Go), github.com/mattermost/mattermost/server/v8 (Go), github.com/mattermost/mattermost-server (Go). Vendors: Go.

Executive brief

Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server

Affected products

  • Go github.com/mattermost/mattermost-server/v5
  • Go github.com/mattermost/mattermost-server/v6
  • Go github.com/mattermost/mattermost/server/v8
  • Go github.com/mattermost/mattermost-server

Related threats