Metrics
Affected Vendors & Products
No advisories yet.
Solution
Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 14 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a remote unauthenticated attacker to register an OAuth client with an attacker-controlled callback host that bypasses the configured redirect URI allowlist via a crafted redirect URI that places an allowlisted host/path suffix inside the query string.. Mattermost Advisory ID: MMSA-2026-00700 | |
| Title | Mattermost DCR redirect URI allowlist bypass via improper URL component validation | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-09-14T19:23:00.625Z
Reserved: 2026-06-23T11:43:37.353Z
Link: CVE-2026-12985
Updated: 2026-09-14T19:15:18.803Z
Status : Received
Published: 2026-09-14T15:17:04.270
Modified: 2026-09-14T20:16:37.930
Link: CVE-2026-12985
No data.
OpenCVE Enrichment
No data.