Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-22545

17
FAUCET Score

CVE-2026-22545 identifies a vulnerability in Mattermost server versions 10.11.x up to 10.11.10, where insufficient validation during an account authentication type switch allows an authenticated attacker to change a user's password without confirmation. Rated with a CVSS score of 3.5 (LOW), this issue requires low privileges and user interaction, potentially leading to low integrity impact by enabling unauthorized password modifications. There is currently no evidence of active exploitation, nor are there any public exploit codes or significant community discussion regarding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 10.11.0, <= 10.11.10CPE match
cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:*
>= 10.11.0, < 10.11.11CPE matchmatch criteria
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.1LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 3rd percentile among its peer group of 406 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

gopatch availablevia ghsa
Product: github.com/mattermost/mattermost/server/v8Fixed in: 8.0.0-20260127144908-ced9a56e3988
gopatch availablevia ghsa
Product: github.com/mattermost/mattermost-serverFixed in: 5.3.2-0.20260127144908-ced9a56e3988
gopatch availablevia ghsa
Product: github.com/mattermost/mattermost-serverFixed in: 10.11.11
gopatch availablevia ghsa
Product: github.com/mattermost/mattermost-serverFixed in: 11.2.3
gopatch availablevia ghsa
Product: github.com/mattermost/mattermost-serverFixed in: 11.3.1

Vendor Advisories (1)

goGHSA-rv67-7w2g-7976low

Mattermost fails to validate user's authentication method when processing account auth type switch

Mar 16, 2026

References

mattermost.com / security-updates
Vendor Advisory