CVE-2026-0999: Authentication bypass via userID login when email and username login are disabled
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-only login requirements via userID-based authentication. Mattermost Advisory ID: MMSA-2025-00548
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0999?
CVE-2026-0999 is considered a high-severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2026-0999?
To remediate CVE-2026-0999, update Mattermost to the latest versions that address the improper validation of login method restrictions.
What versions are affected by CVE-2026-0999?
CVE-2026-0999 affects Mattermost versions 11.1.x up to 11.1.2, 10.11.x up to 10.11.9, and 11.2.x up to 11.2.1.
What causes the CVE-2026-0999 vulnerability?
CVE-2026-0999 is caused by a failure in properly validating login method restrictions which allows bypassing SSO-only login requirements.
Can CVE-2026-0999 lead to further attacks?
Yes, if exploited, CVE-2026-0999 may allow unauthorized access to user accounts, potentially leading to further attacks.