CVE 3.7 LOW

Insufficient token rotation validation in remote cluster invite confirmation_CVE-2026-4273

3.7 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Description

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation which allows an authenticated attacker to bypass token rotation and reuse the original invite token via sending a crafted invite confirmation with a RefreshedToken matching the original token. Mattermost Advisory ID: MMSA-2026-00575

Basic Information

ID CVE-2026-4273
Source Mattermost
Published May 18, 2026 at 06:56

Affected Product

Vendor Mattermost
Product Mattermost
Version 11.5.0
Affected Versions Mattermost Mattermost 11.5.0
Mattermost Mattermost 10.11.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.