OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-96259

MEDIUM · CVSS 5.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Mattermost versions 11.9.x up to 11.9.1, 11.8.x up to 11.8.5, 11.7.x up to 11.7.10, and 11.10.x up to 11.10.1 are vulnerable due to a failure to properly filter internal-connection requests at the OAuth endpoint. This vulnerability allows a System Administrator to exploit the server to access internal network addresses and retrieve sensitive information using OAuth tokens. Organizations using affected Mattermost versions should prioritize remediation to mitigate potential unauthorized access to internal resources.

CVE
CVE-2026-96259
Severity
MEDIUM
CVSS
5.5
EPSS
0.26%

Original NVD Description

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which allows a System Administrator to make the server issue requests to internal network addresses and read the responses via the configured OAuth token and userinfo endpoints.. Mattermost Advisory ID: MMSA-2026-00776

Related CVEs

Other vulnerabilities affecting the same vendor(s)