CVE-2026-2462: Admin RCE via Malicious Plugin Upload on CI Test Instances
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2462?
CVE-2026-2462 is rated as a critical vulnerability due to its ability to allow remote code execution by unauthorized attackers.
How do I fix CVE-2026-2462?
To mitigate CVE-2026-2462, users should upgrade their Mattermost installation to a patched version beyond 11.3.0, 11.2.2, or 10.11.10.
Who is affected by CVE-2026-2462?
CVE-2026-2462 affects Mattermost versions 11.3.x up to 11.3.0, 11.2.x up to 11.2.2, and 10.11.x up to 10.11.10.
What kind of attack does CVE-2026-2462 enable?
CVE-2026-2462 enables an unauthenticated attacker to perform remote code execution by exploiting insufficient restrictions on plugin installation.
What steps should I take if I cannot immediately update from CVE-2026-2462?
If immediate updates are not feasible for CVE-2026-2462, consider disabling plugin functionality and securing admin credentials to minimize exposure.