CVE-2026-3116: Improper Input Validation in Zoom Plugin Webhook Handler
Published Mar 26, 2026
·Updated
Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request size which allows an authenticated attacker to cause service disruption via the webhook endpoint. Mattermost Advisory ID: MMSA-2026-00589
Affected Software
5 affected components
Mattermost Mattermost Zoom Plugin<=11.4, =11.0.4, =11.1.3, =11.3.2, =10.11.11.0
Mattermost Mattermost Server>=10.11.0<10.11.12
Mattermost Mattermost Server>=11.2.0<11.2.4
Mattermost Mattermost Server>=11.3.0<11.3.2
Mattermost Mattermost Server>=11.4.0<11.4.1
Remediation
Information
Update Mattermost Plugins to versions 11.5.0, 11.4.1, 11.3.2, 11.2.4, 10.11.12 or higher.
Event History
Mar 26, 2026
CVE Published
via MITRE·04:19 PM
Data Sourced
via MITRE·04:19 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-3116?
CVE-2026-3116 has a medium severity level due to its potential for service disruption.
2
How do I fix CVE-2026-3116?
To fix CVE-2026-3116, update the Mattermost Zoom Plugin to a version that is greater than 11.4.
3
What versions are affected by CVE-2026-3116?
CVE-2026-3116 affects Mattermost Zoom Plugin versions up to and including 11.4, as well as versions 11.0.4, 11.1.3, 11.3.2, and 10.11.11.0.
4
What type of vulnerability is CVE-2026-3116?
CVE-2026-3116 is an improper input validation vulnerability.
5
Who can exploit CVE-2026-3116?
CVE-2026-3116 can be exploited by authenticated attackers through the webhook endpoint.