Executive brief
Mattermost is a team collaboration platform that organizations use for internal communication. A flaw in certain versions allows system administrators to bypass network security controls and make the server request data from internal network resources, potentially exposing sensitive internal services or information.
Technical details
The vulnerability is a failure to apply the internal-connection filter to OAuth endpoint requests, allowing authenticated system administrators to make the Mattermost server issue requests to internal network addresses. An attacker with system administrator privileges can read responses from configured OAuth token and userinfo endpoints that would normally be restricted from accessing internal resources.
Affected products
- Mattermost Mattermost Server 11.7.x through 11.7.10, 11.8.x through 11.8.5, 11.9.x through 11.9.1, 11.10.x through 11.10.1
Timeline
- 2026-09-22: disclosed