CVE-2026-3590: Race Condition in Guest Magic Link Authentication Allows Token Reuse
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid magic link to establish multiple independent authenticated sessions via concurrent requests.. Mattermost Advisory ID: MMSA-2026-00624
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3590?
CVE-2026-3590 is classified as a medium severity vulnerability due to the risk of guest tokens being reused by attackers.
How do I fix CVE-2026-3590?
To fix CVE-2026-3590, update Mattermost to versions later than 10.11.12, 11.5.0, 11.4.2, or 11.3.2.
What does CVE-2026-3590 exploit?
CVE-2026-3590 exploits a race condition in guest magic link authentication, allowing token reuse.
Who is affected by CVE-2026-3590?
CVE-2026-3590 affects Mattermost versions 10.11.x up to 10.11.12, 11.5.x up to 11.5.0, 11.4.x up to 11.4.2, and 11.3.x up to 11.3.2.
What is the risk associated with CVE-2026-3590?
The risk associated with CVE-2026-3590 includes unauthorized access by attackers using valid magic link tokens.