CVE-2026-3117
EUVD-2026-3074818.05.2026, 09:16
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin which allows normal users to uninstall instances or setup webhook connections via the {{gitlab instance {option}}} or the {{/gitlab webhook {option}}} commands. Mattermost Advisory ID: MMSA-2026-00600EnginsightEarly Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mattermost | mattermost | 𝑥 ≤ 11.1.5 | CNA |
| mattermost | mattermost | 𝑥 ≤ 10.13.11 | CNA |
| mattermost | mattermost | 𝑥 ≤ 11.3.4 | CNA |
Common Weakness Enumeration
References