OVERVIEW CVE-2026-3590 is a token validation flaw in Mattermost (Mattermost Advisory ID: MMSA-2026-00624) affecting versions 10.11.x through 10.11.12, 11.5.x through 11.5.0, 11.4.x through 11.4.2, and 11.3.x through 11.3.2. The vulnerability fails to enforce atomic single-use consumption of guest magic link tokens, enabling attackers to leverage a single valid magic link to create multiple concurrent authenticated sessions. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.5 (Medium) with a network-based attack vector requiring no authentication or user interaction. Attack complexity is low, meaning exploitation can be readily performed. The impact includes low-level confidentiality and integrity compromise, though availability is not affected. The FAUCET Risk Score of 45.0/100 indicates moderate risk, while the EPSS score of 0.000340 suggests minimal current exploitation likelihood relative to the broader CVE landscape. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. No public exploit code has been disclosed. These indicators suggest the issue remains primarily a concern for proactive patching rather than an immediate threat requiring emergency remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.11.0, <= 10.11.12CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 11.3.0, <= 11.3.2CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 11.4.0, <= 11.4.2CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 11.5.0, <= 11.5.0CPE match | cpe:2.3:a:mattermost:mattermost:*:*:*:*:*:*:*:* | ||
>= 10.11.0, < 10.11.13CPE matchmatch criteria | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.