CyberRota Analysis
AI-GeneratedMattermost versions 11.7.x up to 11.7.6 and 10.11.x up to 10.11.21 are vulnerable due to inadequate restrictions on OAuth deauthorization and personal access token management endpoints, allowing OAuth apps to revoke user tokens for other integrations. This could lead to unauthorized access and disruption of services for affected users. Organizations using these Mattermost versions should prioritize patching to mitigate potential security risks.
Original NVD Description
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and personal access token management endpoints to direct user sessions, which allowed an OAuth app with a delegated user token to revoke the user's authorizations or tokens for other integrations via account-management endpoints.. Mattermost Advisory ID: MMSA-2026-00704
Related CVEs
Other vulnerabilities affecting the same vendor(s)