Executive brief
Mattermost is a team communication platform that integrates with Jira through Atlassian Connect. Affected versions fail to authenticate callbacks during Jira integration setup, allowing an unauthenticated attacker to inject a malicious shared secret and disrupt the Jira integration, potentially compromising the integrity of linked issues and workflows.
Technical details
The vulnerability is a missing authentication issue (CWE-306) in Mattermost's Atlassian Connect integration. The /ac/installed endpoint fails to properly authenticate callbacks from Atlassian Connect during the Jira app installation phase, allowing an unauthenticated attacker with network access to POST a malicious payload containing a rogue sharedSecret. This occurs within a time window when the integration is pending installation. The attacker can inject a false shared secret used for subsequent HMAC verification, disrupting the integrity of the Jira integration and potentially enabling further manipulation of integrated workflows. The attack requires low privileges and user interaction (likely admin-level actions to enable/install the integration). Patches are available: 11.7.1, 11.6.3, 11.5.6, and 10.11.18.
Affected products
- Mattermost Mattermost Server 11.7.0, 11.6.0–11.6.2, 11.5.0–11.5.5, 10.11.0–10.11.17
Timeline
- 2026-06-22: disclosed
- 2026-06-22: patched: Patches released: 11.7.1, 11.6.3, 11.5.6, 10.11.18