CVE-2026-28741: CSRF Protection Bypass Allows Updating a User's Authentication Method
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpoint which allows an attacker to update a user's authentication method via a CSRF attack by tricking a user into visiting a malicious page. Mattermost Advisory ID: MMSA-2026-00625
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28741?
CVE-2026-28741 is classified as a medium severity vulnerability due to its potential impact on user security.
How do I fix CVE-2026-28741?
To fix CVE-2026-28741, users should upgrade their Mattermost installation to a version that addresses the CSRF protection bypass.
What versions are affected by CVE-2026-28741?
CVE-2026-28741 affects Mattermost versions 10.11.0 to 10.11.12, 11.4.0 to 11.4.2, 11.3.0 to 11.3.2, and exactly 11.5.0.
What are the potential consequences of CVE-2026-28741?
If exploited, CVE-2026-28741 allows an attacker to potentially change a user's authentication method, leading to unauthorized access.
Is there a workaround for CVE-2026-28741?
There is no official workaround for CVE-2026-28741; the recommended action is to upgrade to a patched version of Mattermost.