Home
MEDIUM: 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NDefault status
unaffected
11.6.0 (semver)
affected
11.5.0 (semver)
affected
11.4.0 (semver)
affected
10.11.0 (semver)
affected
11.7.0
unaffected
11.6.1
unaffected
11.5.4
unaffected
11.4.5
unaffected
10.11.15
unaffected
Description
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying the scope parameter in the GitHub authorization URL.. Mattermost Advisory ID: MMSA-2026-00628
Problem types
CWE-863: Incorrect Authorization
Product status
11.6.0 (semver)
11.5.0 (semver)
11.4.0 (semver)
10.11.0 (semver)
11.7.0
11.6.1
11.5.4
11.4.5
10.11.15
Credits
eahmed
References
mattermost.com/security-updates (MMSA-2026-00628)