CVE-2026-2299: Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint
The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermost Google Drive pluginto a version that resolves this vulnerability.Fixed in 1.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2299?
CVE-2026-2299 has a medium severity rating of 4.2.
How do I fix CVE-2026-2299?
To fix CVE-2026-2299, upgrade the Mattermost Google Drive plugin to version 1.1.0 or later.
What is the impact of CVE-2026-2299?
CVE-2026-2299 allows unauthorized sharing of Google Drive files to private channels, potentially disclosing private channel membership.
Who is affected by CVE-2026-2299?
Users of the Mattermost Google Drive plugin prior to version 1.1.0 are affected by CVE-2026-2299.
What conditions are needed for CVE-2026-2299 to be exploited?
CVE-2026-2299 can be exploited by authenticated users with a connected Google account who can access the file creation endpoint.