SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16045

MEDIUM · CVSS 4.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

Mattermost versions 11.7.x up to 11.7.6 and 10.11.x up to 10.11.21 are vulnerable due to inadequate restrictions on OAuth deauthorization and personal access token management endpoints, allowing OAuth apps to revoke user tokens for other integrations. This could lead to unauthorized access and disruption of services for affected users. Organizations using these Mattermost versions should prioritize patching to mitigate potential security risks.

CVE
CVE-2026-16045
Severity
MEDIUM
CVSS
4.3
EPSS
0.19%

Original NVD Description

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and personal access token management endpoints to direct user sessions, which allowed an OAuth app with a delegated user token to revoke the user's authorizations or tokens for other integrations via account-management endpoints.. Mattermost Advisory ID: MMSA-2026-00704

Related CVEs

Other vulnerabilities affecting the same vendor(s)