CVE-2026-12985: Mattermost DCR redirect URI allowlist bypass via improper URL component validation

Published Sep 14, 2026
·
Updated

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a remote unauthenticated attacker to register an OAuth client with an attacker-controlled callback host that bypasses the configured redirect URI allowlist via a crafted redirect URI that places an allowlisted host/path suffix inside the query string.. Mattermost Advisory ID: MMSA-2026-00700

Affected Software

1 affected component
Mattermost Mattermost>11.7.0<=11.7.7, >11.8.0<=11.8.4, >11.9.0<=11.9.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Mattermost to a version that resolves this vulnerability.

    Fixed in 11.10.0
  2. Upgrade

    Upgrade Mattermost to a version that resolves this vulnerability.

    Fixed in 11.9.1
  3. Upgrade

    Upgrade Mattermost to a version that resolves this vulnerability.

    Fixed in 11.8.5
  4. Upgrade

    Upgrade Mattermost to a version that resolves this vulnerability.

    Fixed in 11.7.8
  5. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch MMSA-2026-00700

Event History

Sep 14, 2026
CVE Published
via MITRE·02:09 PM
Data Sourced
via MITRE·02:09 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Mattermost deployments running 11.9.0 or earlier in the 11.9.x line, 11.8.4 or earlier in the 11.8.x line, or 11.7.7 or earlier in the 11.7.x line are affected. Exploitation concerns the Dynamic Client Registration OAuth feature and its configured redirect URI allowlist.

2

What does an attacker need to exploit this issue?

An attacker can be remote and unauthenticated, but exploitation requires user interaction. They register an OAuth client with a crafted redirect URI whose query string contains an allowlisted host or path suffix while the actual callback host is attacker-controlled.

3

How can teams identify potentially affected OAuth client registrations?

Review Dynamic Client Registration redirect URIs for entries where an allowlisted host or path appears only within the query string rather than as the parsed redirect URI host and path. Such registrations may have bypassed the intended allowlist validation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203