Executive brief
Mattermost, a collaboration and messaging platform, contains a security flaw that could allow an attacker to discover user passwords. By obtaining these credentials, a malicious actor could impersonate legitimate users, potentially gaining unauthorized access to sensitive internal communications and private data. This issue primarily affects specific versions of the Mattermost server during certain user creation or import processes.
Technical details
Mattermost Server is vulnerable to credential disclosure (CWE-522) in versions 11.5.x, 11.4.x, and 10.11.x. The root cause involves the failure to prevent the disclosure of created user passwords, particularly during processes like Slack imports. An attacker with high privileges (PR:H) can exploit this over the network to retrieve or intercept passwords, enabling user impersonation. The fix, as seen in commit 3057ae7, involves improving the Slack import flow to add users without pre-set passwords and forcing a password reset flow instead. Patches are available in versions 11.5.2, 11.4.4, and 10.11.14.
Affected products
- Mattermost Mattermost Server 11.5.0 - 11.5.1, 11.4.0 - 11.4.3, 10.11.0 - 10.11.13, and versions prior to 8.0.0-20260311102650-3057ae7e83e9
Timeline
- 2026-03-11: patched: Fix commit 3057ae7e83e9c827ce7818d67c0f3a208f0d9709 authored
- 2026-05-18: disclosed: NVD and GitHub Advisory published