CVE-2026-27769: Mattermost Server

Low severity, CVSS 2.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed status of local users via the Connected Workspaces API.. Mattermost Advisory ID: MMSA-2026-00603

Affected products

  • Mattermost Mattermost Server: from 10.11.0, before 10.11.13 (fixed in 10.11.13)

Published 2026-04-15. Last modified 2026-06-17.