Executive brief
A security flaw in the Mattermost GitLab plugin allows standard users to perform administrative actions they should not have access to. Specifically, unauthorized users can uninstall GitLab instances or modify webhook connections within the collaboration platform. This could lead to service disruptions and unauthorized changes to how the platform integrates with development workflows.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Mattermost GitLab plugin. The software fails to properly validate user permissions when processing specific slash commands, namely 'gitlab instance {option}' and '/gitlab webhook {option}'. An authenticated user with standard privileges can exploit this over the network to perform administrative tasks such as uninstalling GitLab instances or setting up unauthorized webhook connections. The vulnerability affects versions up to 11.5, as well as 11.1.5, 10.13.11, and 11.3.4.0. Users are advised to update to the latest patched versions provided by Mattermost.
Affected products
- Mattermost GitLab Plugin <=11.5, 11.1.5, 10.13.11, 11.3.4.0
Timeline
- 2026-05-18: disclosed: CVE published by NVD and Mattermost