CVE-2026-6334 PUBLISHED

OAuth authorization code client binding not enforced during token redemption in Mattermost

Assigner: Mattermost
Reserved: 15.04.2026 Published: 18.05.2026 Updated: 18.05.2026

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth authorization code redemption flow which allows an authenticated OAuth client to redeem authorization codes issued to a different client via a crafted token exchange request.. Mattermost Advisory ID: MMSA-2026-00570

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
CVSS Score: 3.1

Product Status

Vendor Mattermost
Product Mattermost
Versions Default: unaffected
  • affected from 11.5.0 to 11.5.1 (incl.)
  • affected from 10.11.0 to 10.11.13 (incl.)
  • Version 11.6.0 is unaffected
  • Version 11.5.2 is unaffected
  • Version 10.11.14 is unaffected

Solutions

Update Mattermost to versions 11.6.0, 11.5.2, 10.11.14 or higher.

Credits

  • Dylan Haussermann finder

References

Problem Types

  • CWE-305 – Authentication Bypass by Primary Weakness CWE