CVE-2026-3109: Mattermost Server
Low severity, CVSS 2.2. EPSS: 0.3% chance of exploitation in the next 30 days.
Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to corrupt Zoom meeting state in Mattermost via replayed webhook requests. Mattermost Advisory ID: MMSA-2026-00584
Affected products
- Mattermost Mattermost Server: from 10.11.0, before 10.11.12 (fixed in 10.11.12)
Published 2026-03-26. Last modified 2026-06-17.