CVE-2026-96259: Mattermost server-side request forgery via OAuth endpoints configurable by a System Administrator
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which allows a System Administrator to make the server issue requests to internal network addresses and read the responses via the configured OAuth token and userinfo endpoints.. Mattermost Advisory ID: MMSA-2026-00776
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.11.0Patch MMSA-2026-00776 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.9.2Patch MMSA-2026-00776 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.6Patch MMSA-2026-00776 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.11Patch MMSA-2026-00776 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.10.2Patch MMSA-2026-00776
Event History
Frequently Asked Questions
What level of access is required to exploit this issue?
Exploitation requires System Administrator privileges. The administrator must be able to configure the OAuth token and userinfo endpoints.
What can an attacker do after exploiting the issue?
They can cause the Mattermost server to issue requests to internal network addresses. Responses can be read through the configured OAuth token and userinfo endpoints.