Executive brief
Mattermost, a collaboration platform for secure communication, contains a flaw in how it handles connections between different server clusters. An attacker can bypass security measures intended to rotate secret tokens, allowing them to reuse an old invitation token that should have been retired. This could potentially allow unauthorized persistent access or connection between server environments.
Technical details
An authorization bypass vulnerability (CWE-863) exists in Mattermost Server's remote cluster invitation logic. The component fails to verify that the 'RefreshedToken' provided during the invite confirmation process is distinct from the original invitation token. By sending a crafted invite confirmation where the RefreshedToken matches the original token, an attacker can bypass the intended token rotation mechanism. This allows for the continued use of the original token. The vulnerability is fixed in versions 11.5.2, 10.11.14, and specific backported builds of version 8.0.0.
Affected products
- Mattermost Mattermost Server 11.5.0 - 11.5.1, 10.11.0 - 10.11.13, < 8.0.0-20260313190740-742e0be95074
Timeline
- 2026-05-18: disclosed: Initial disclosure and NVD publication
- 2026-05-18: advisory: Mattermost Advisory MMSA-2026-00575 published
- 2026-06-01: patched: GitHub advisory reviewed and updated with patch details