PatchSiren cyber security CVE debrief
CVE-2026-4273 Mattermost CVE debrief
A vulnerability in Mattermost Server versions 11.5.x through 11.5.1 and 10.11.x through 10.11.13 allows an authenticated attacker to bypass token rotation during remote cluster invite confirmation. The root cause is a missing validation check that the RefreshedToken differs from the original invite token. By sending a crafted invite confirmation with a RefreshedToken matching the original token, an attacker can reuse the original invite token despite the intended rotation mechanism. This weakness is classified as CWE-863 (Incorrect Authorization). The CVSS 3.1 score of 3.7 (Low severity) reflects the attack complexity requirements and limited impact scope. The vulnerability was disclosed on May 18, 2026, with the NVD entry subsequently analyzed on May 19, 2026. Mattermost has published security updates addressing this issue.
- Vendor
- Mattermost
- Product
- Unknown
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-18
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-18
- Advisory updated
- 2026-05-19
Who should care
Mattermost Server administrators operating multi-cluster deployments with remote cluster invite functionality enabled; security teams responsible for identity and access management in Mattermost environments; compliance officers tracking token lifecycle management controls.
Technical summary
The vulnerability exists in the remote cluster invite confirmation handler where the server fails to validate that a newly generated RefreshedToken is distinct from the original invite token. An authenticated attacker can exploit this by crafting an invite confirmation request where the RefreshedToken field equals the original token value. This causes the server to accept the confirmation while preserving the original token's validity, effectively nullifying the security benefit of token rotation. The attack requires network access to the Mattermost server and knowledge of the original invite token, but does not require user interaction. The integrity impact is limited (low) as the attack does not enable privilege escalation beyond the scope of the original invite token's intended use.
Defensive priority
low
Recommended defensive actions
- Upgrade Mattermost Server to version 10.11.14 or later, or version 11.5.2 or later, to remediate this vulnerability.
- Review remote cluster invite confirmation workflows for any anomalous token reuse patterns in audit logs.
- Verify that security update channels are configured to receive Mattermost security advisories promptly.
Evidence notes
Vulnerability confirmed via NVD CPE criteria and Mattermost vendor advisory. Affected versions explicitly listed as 10.11.0 through 10.11.13 and 11.5.0 through 11.5.1. CVSS vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N sourced from NVD. CWE-863 classification from vendor disclosure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-4273 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-4273
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-4273 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-4273
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://mattermost.com/security-updates
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.