Launch Week Day 1: Announcing Security Design Review
LOW 3.1 Go

Mattermost fails to validate user's authentication method when processing account auth type switch

GHSA-rv67-7w2g-7976 · CVE-2026-22545 · GO-2026-4786

Published · Modified

Description

Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth type switch which allows an authenticated attacker to change account password without confirmation via falsely claiming a different auth provider.. Mattermost Advisory ID: MMSA-2026-00583

Ready to move

Start Securing

Free, no credit card | First findings in minutes