CVE-2024-2450: Mattermost Server

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email to SAML authentication, allowing an authenticated attacker to take over other user accounts via a crafted switch request under specific conditions.

Affected products

  • Mattermost Mattermost Server: from 8.1.0, before 8.1.10 (fixed in 8.1.10); from 9.2.0, before 9.2.6 (fixed in 9.2.6); from 9.3.0, before 9.3.2 (fixed in 9.3.2); from 9.4.0, before 9.4.3 (fixed in 9.4.3); version 9.5.0 only

Published 2024-03-15. Last modified 2026-06-17.