Subscriptions
No data.
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
Update Mattermost Plugins to versions 11.5.0, 10.11.12 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Thu, 26 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to corrupt Zoom meeting state in Mattermost via replayed webhook requests. Mattermost Advisory ID: MMSA-2026-00584 | |
| Title | Missing timestamp validation in Zoom webhook handler | |
| Weaknesses | CWE-754 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-03-26T19:52:11.107Z
Reserved: 2026-02-24T10:53:41.124Z
Link: CVE-2026-3109
Updated: 2026-03-26T19:50:43.961Z
Status : Received
Published: 2026-03-26T17:16:41.967
Modified: 2026-03-26T17:16:41.967
Link: CVE-2026-3109
No data.
OpenCVE Enrichment
No data.