CVE-2026-22545 identifies a vulnerability in Mattermost server versions 10.11.x up to 10.11.10, where insufficient validation during an account authentication type switch allows an authenticated attacker to change a user's password without confirmation. Rated with a CVSS score of 3.5 (LOW), this issue requires low privileges and user interaction, potentially leading to low integrity impact by enabling unauthorized password modifications. There is currently no evidence of active exploitation, nor are there any public exploit codes or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.11.0, <= 10.11.10CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 10.11.0, < 10.11.11CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.