Junglewise Threat Intelligence

CVE-2026-6342: Mattermost Plugins incorrect authorization in group subscriptions

CVE-2026-6342 · Severity: medium · CVSS 4.3 · Published 2026-05-18

Technologies: Mattermost Plugins. Vendors: Mattermost.

Executive brief

Mattermost Plugins, which extend the functionality of the Mattermost collaboration platform, contain a security flaw in how they manage group subscriptions. An authorized user could bypass intended restrictions to join or subscribe to groups that should be off-limits by exploiting a naming inconsistency. This could lead to unauthorized access to group-based communications or notifications that were meant to be restricted to specific whitelisted sets.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Mattermost Plugins due to insufficient namespace validation. The software fails to strictly enforce whitelisting for group subscriptions, allowing an attacker with low-level privileges to subscribe to unauthorized groups if those groups share a name prefix with a legitimate, whitelisted group. This is a network-reachable vulnerability that requires authentication but no user interaction. The flaw allows for unauthorized integrity changes regarding group subscriptions. Fixes are typically addressed in subsequent Mattermost release cycles.

Affected products

  • Mattermost Mattermost Plugins <=11.5, 11.1.5, 10.13.11, 11.3.4.0

Timeline

  • 2026-05-18: disclosed: CVE published by NVD and Mattermost

References

Related threats