Description
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and personal access token management endpoints to direct user sessions, which allowed an OAuth app with a delegated user token to revoke the user's authorizations or tokens for other integrations via account-management endpoints.. Mattermost Advisory ID: MMSA-2026-00704
Published: 2026-08-17
Score: 2.7 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost did not limit OAuth deauthorization and personal access token management endpoints to active user sessions. This bug allows an OAuth application that holds a delegated user token to revoke tokens or authorizations for other integrations via account‑management endpoints. The resulting loss of integration tokens can cause service interruption for connected applications, affecting data access and workflow continuity.

Affected Systems

Mattermost Community and Enterprise editions versions 11.7.x through 11.7.6 and 10.11.x through 10.11.21 are impacted. Upgrading to the following releases restores proper session scoping to protect OAuth authorizations: 11.9.0, 11.7.7, or 10.11.22 and later.

Risk and Exploitability

The publicly reported severity is CVSS 2.7, indicating low impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. An attacker would need to possess a delegated OAuth token or have authority to create an application with such a token. The attack vector is inferred to be application‑level and requires authentication, which limits immediate exploitation risk.

Generated by OpenCVE AI on August 17, 2026 at 15:17 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.9.0, 11.7.7, 10.11.22 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to version 11.9.0, 11.7.7, 10.11.22 or newer to apply the vendor fix.
  • Configure OAuth scopes carefully, ensuring applications only request the minimum permissions required and remove any unused or unnecessary integration tokens.
  • Enable and review audit logs for token creation, revocation, and account‑management activities to detect unauthorized or suspicious actions.

Generated by OpenCVE AI on August 17, 2026 at 15:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 17 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 17 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and personal access token management endpoints to direct user sessions, which allowed an OAuth app with a delegated user token to revoke the user's authorizations or tokens for other integrations via account-management endpoints.. Mattermost Advisory ID: MMSA-2026-00704
Title Delegated OAuth tokens could revoke unrelated OAuth application authorizations
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-08-17T15:26:05.729Z

Reserved: 2026-07-17T09:41:38.446Z

Link: CVE-2026-16045

cve-icon Vulnrichment

Updated: 2026-08-17T15:26:00.686Z

cve-icon NVD

Status : Received

Published: 2026-08-17T15:16:53.967

Modified: 2026-08-17T16:16:50.560

Link: CVE-2026-16045

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T15:30:06Z

Weaknesses