CVE-2026-6342: Group prefix matching bypass for subscriptions
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriately check for valid namespaces which allows plugin users to create subscriptions to groups that were not whitelisted via creating groups that share the same prefix as a whitelisted group. Mattermost Advisory ID: MMSA-2026-00601
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MMSA-2026-00601 - Upgrade
Upgrade
Mattermost Pluginsto a version that resolves this vulnerability.Fixed in 11.6.0 - Upgrade
Upgrade
Mattermost Pluginsto a version that resolves this vulnerability.Fixed in 11.5.2 - Upgrade
Upgrade
Mattermost Pluginsto a version that resolves this vulnerability.Fixed in 10.11.14 - Upgrade
Upgrade
Mattermost Pluginsto a version that resolves this vulnerability.Fixed in 11.4.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6342?
CVE-2026-6342 is categorized as a medium severity vulnerability due to its potential impact on group subscription management.
How do I fix CVE-2026-6342?
To fix CVE-2026-6342, update to Mattermost Plugins version 11.5 or later, or apply any available patches that address this issue.
What versions are affected by CVE-2026-6342?
CVE-2026-6342 affects Mattermost Plugins versions up to and including 11.5, 11.1.5, 10.13.11, and 11.3.4.0.
What is the impact of CVE-2026-6342?
The impact of CVE-2026-6342 allows unauthorized users to subscribe to groups by exploiting namespace prefix matching.
Is CVE-2026-6342 being actively exploited?
As of the latest reports, there is no indication that CVE-2026-6342 is being actively exploited, but it is recommended to apply fixes promptly.