CVE-2026-6673: Mattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud install
Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret and disrupt the Jira integration via POST to /ac/installed during the pending-install window.. Mattermost Advisory ID: MMSA-2026-00654
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.1 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.6.3 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.5.6 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6673?
The severity of CVE-2026-6673 is medium with a score of 6.4.
How do I fix CVE-2026-6673?
To fix CVE-2026-6673, update your Mattermost installation to a version that addresses the unauthenticated callbacks on the Atlassian Connect.
What kind of attack is possible due to CVE-2026-6673?
CVE-2026-6673 allows a remote unauthenticated attacker to inject a rogue sharedSecret, potentially disrupting the Jira integration.
Which Mattermost versions are affected by CVE-2026-6673?
Affected versions include Mattermost versions 11.7.x up to 11.7.0, 11.6.x up to 11.6.2, 11.5.x up to 11.5.5, and 10.11.x up to 10.11.17.
Is authentication required for exploiting CVE-2026-6673?
Authentication is not required for exploiting CVE-2026-6673, making it easier for attackers to execute the vulnerability.