Junglewise Threat Intelligence

CVE-2026-3590: Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement

CVE-2026-3590 · Severity: medium · CVSS 6.5 · Published 2026-04-17

Technologies: github.com/mattermost/mattermost-server/v6 (Go), github.com/mattermost/mattermost/server/v8 (Go), github.com/mattermost/mattermost-server/v5 (Go), github.com/mattermost/mattermost-server (Go). Vendors: Go.

Executive brief

Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid magic link to establish multiple independent authenticated sessions via concurrent requests. Mattermost Advisory ID: MMSA-2026-00624.

Affected products

  • Go github.com/mattermost/mattermost-server/v6
  • Go github.com/mattermost/mattermost/server/v8
  • Go github.com/mattermost/mattermost-server/v5
  • Go github.com/mattermost/mattermost-server

References

Related threats