PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-2299 Mattermost CVE debrief

The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership. This vulnerability has a CVSS score of 4.2 and a severity of MEDIUM. The vulnerability is caused by a lack of validation in the file creation endpoint, which allows attackers to share files with unauthorized users. Evidence limits suggest that further verification is needed to confirm affected scope and severity. Defenders should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed to ensure proper mitigation and remediation. Mattermost Google Drive plugin users should update to version 1.1.0 or later. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Review compensating controls for exposed systems while remediation is scheduled and verified.

Vendor
Mattermost
Product
Mattermost Google Drive Plugin
CVSS
MEDIUM 4.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-25
Original CVE updated
2026-08-11
Advisory published
2026-06-25
Advisory updated
2026-08-11

Who should care

Mattermost Google Drive plugin users, administrators of Mattermost instances with the Google Drive plugin installed, and users with connected Google accounts should be aware of this vulnerability and take necessary actions to protect their systems. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed to ensure proper mitigation and remediation.

Technical summary

The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership. This vulnerability has a CVSS score of 4.2 and a severity of MEDIUM. The vulnerability is caused by a lack of validation in the file creation endpoint, which allows attackers to share files with unauthorized users.

Defensive priority

Authenticated users with a connected Google account can share Google Drive files to unauthorized private channels, disclosing private channel membership. Mattermost Google Drive plugin users should update to version 1.1.0 or later.

Recommended defensive actions

  • Update Mattermost Google Drive plugin to version 1.1.0 or later
  • Restrict file sharing to authorized channels
  • Monitor plugin version and update as necessary
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint. Official CVE and NVD records provide details on the vulnerability. Evidence limits suggest that further verification is needed to confirm affected scope and severity. Defenders should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-25T20:17:10.763Z and has not been modified since then.