CVE-2023-2193: Mattermost

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app, allowing an attacker possessing an authorization code to generate an access token.

Affected products

  • Mattermost Mattermost: version 7.1.7 only; version 7.7.3 only; version 7.8.2 only; version 7.9.1 only

Published 2023-04-20. Last modified 2026-06-17.