We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite via the REST API.
Reserved 2025-06-18 | Published 2025-07-18 | Updated 2025-07-18 | Assigner MattermostCWE-522: Insufficiently Protected Credentials
Miguel de la Cruz
mattermost.com/security-updates
Support options