CVE-2026-2462: Admin RCE via Malicious Plugin Upload on CI Test Instances

Published Mar 16, 2026
·
Updated

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528

Affected Software

4 affected components
Mattermost Mattermost<=11.3.0, <=11.2.2, <=10.11.10
Mattermost Mattermost Server>=10.11.0<10.11.11
Mattermost Mattermost Server>=11.2.0<11.2.3
Mattermost Mattermost Server>=11.3.0<11.3.1

Remediation

Information

Update Mattermost to versions 11.4.0, 11.3.1, 11.2.3, 10.11.11 or higher.

Event History

Mar 16, 2026
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:19 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-2462?

CVE-2026-2462 is rated as a critical vulnerability due to its ability to allow remote code execution by unauthorized attackers.

2

How do I fix CVE-2026-2462?

To mitigate CVE-2026-2462, users should upgrade their Mattermost installation to a patched version beyond 11.3.0, 11.2.2, or 10.11.10.

3

Who is affected by CVE-2026-2462?

CVE-2026-2462 affects Mattermost versions 11.3.x up to 11.3.0, 11.2.x up to 11.2.2, and 10.11.x up to 10.11.10.

4

What kind of attack does CVE-2026-2462 enable?

CVE-2026-2462 enables an unauthenticated attacker to perform remote code execution by exploiting insufficient restrictions on plugin installation.

5

What steps should I take if I cannot immediately update from CVE-2026-2462?

If immediate updates are not feasible for CVE-2026-2462, consider disabling plugin functionality and securing admin credentials to minimize exposure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203