Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a remote unauthenticated attacker to register an OAuth client with an attacker-controlled callback host that bypasses the configured redirect URI allowlist via a crafted redirect URI that places an allowlisted host/path suffix inside the query string.. Mattermost Advisory ID: MMSA-2026-00700
Published: 2026-09-14
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized OAuth Client Registration
Action: Patch
AI Analysis

Impact

The vulnerability arises from Mattermost’s failure to properly validate dynamic client registration redirect URIs. Instead of parsing the URL, the system matches glob patterns against the entire raw string. This flaw allows an attacker to craft a redirect URI that embeds an allowlisted host or path suffix within the query string, thereby bypassing the configured redirect URI allowlist. A remote and unauthenticated attacker can use this to register an OAuth client with a malicious callback host, potentially intercepting authorization codes or tokens.

Affected Systems

Mattermost deployments running versions 11.9.x (<=11.9.0), 11.8.x (<=11.8.4), or 11.7.x (<=11.7.7) are susceptible. The affected product is the Mattermost server component as documented by the Mattermost CNA. The official fix is available by upgrading to any of the following minimum versions: 11.10.0, 11.9.1, 11.8.5, or 11.7.8, which correct the redirect URI validation logic.

Risk and Exploitability

The CVSS score of 6.8 classifies this issue as moderate severity. There is currently no EPSS data, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is straightforward: an unauthenticated client can send a crafted registration request to the DCR endpoint, bypass the allowlist, and register a hostile OAuth client. Because the endpoint is publicly reachable and no authentication is required, the likelihood of exploitation is considered significant in environments with exposed Mattermost APIs.

Generated by OpenCVE AI on September 15, 2026 at 07:11 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8 or higher.


OpenCVE Recommended Actions

  • Upgrade to at least Mattermost version 11.10.0 (or 11.9.1, 11.8.5, 11.7.8) to apply the official fix.
  • If an upgrade cannot be performed immediately, block or severely restrict access to the Dynamic Client Registration endpoint to prevent new registrations.
  • After applying the patch, confirm that the redirect URI allowlist configuration enforces host and path validation correctly and monitor logs for any new OAuth client registration attempts.

Generated by OpenCVE AI on September 15, 2026 at 07:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 15 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a remote unauthenticated attacker to register an OAuth client with an attacker-controlled callback host that bypasses the configured redirect URI allowlist via a crafted redirect URI that places an allowlisted host/path suffix inside the query string.. Mattermost Advisory ID: MMSA-2026-00700
Title Mattermost DCR redirect URI allowlist bypass via improper URL component validation
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-15T03:56:02.615Z

Reserved: 2026-06-23T11:43:37.353Z

Link: CVE-2026-12985

cve-icon Vulnrichment

Updated: 2026-09-14T19:15:18.803Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T15:17:04.270

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-12985

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T07:15:17Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')