SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-16049

MEDIUM · CVSS 4.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

The Mattermost GitLab plugin in versions up to 11.8, 10.20.11, and 11.5.7.0 is vulnerable due to inadequate verification of channel permissions and insufficient validation of API parameters, allowing authenticated attackers to inject unauthorized bot-authored messages with arbitrary URLs into restricted channels. This could lead to potential phishing attacks or the spread of malicious content within the organization. Organizations using affected versions of GitLab should prioritize patching to mitigate these risks.

CVE
CVE-2026-16049
Severity
MEDIUM
CVSS
4.3
EPSS
0.22%
GitLab

Original NVD Description

Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails to validate the_ {{web_url}} _parameter against the configured GitLab instance, which allows an authenticated attacker to inject bot-authored messages containing arbitrary URLs into channels they do not have access to via the_ {{createIssue}} _and_ {{attachCommentToIssue}} _API endpoints._ Mattermost Advisory ID: MMSA-2026-00673