CVE-2026-0998 is a medium-severity vulnerability affecting Mattermost versions 11.1.x, 10.11.x, 11.2.x, and the Mattermost Zoom plugin up to version 1.11.0. It allows unauthorized users to initiate Zoom meetings as other users and overwrite arbitrary posts due to insufficient validation of user identity and post ownership in the /api/v1/askPMI endpoint. With a CVSS score of 4.3, this vulnerability has a low attack complexity and requires low privileges, but does not impact confidentiality or availability, only integrity. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it has received limited media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.11.0, <= 10.11.9CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 11.1.0, <= 11.1.2CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 11.2.0, <= 11.2.1CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 10.11.0, < 10.11.10CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | ||
>= 11.1.0, < 11.1.3CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.