Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-9571— Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in Mattermost

CVSS 5.9 · Medium EPSS 0.17% · P7

Possible ATT&CK Techniques 1AI

T1528 · Steal Application Access Token

Affected Version Matrix 7

VendorProductVersion RangeStatus
MattermostMattermost11.7.0≤ 11.7.2affected
11.6.0≤ 11.6.4affected
10.11.0≤ 10.11.19affected
11.8.0unaffected
11.7.3unaffected
11.6.5unaffected
10.11.20unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-9571

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in Mattermost
Source: CVE Program / CVE List V5
Vulnerability Description
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint.. Mattermost Advisory ID: MMSA-2026-00680
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用基本弱点进行的认证绕过
Source: CVE Program / CVE List V5
Vulnerability Title
Mattermost 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mattermost是美国Mattermost公司开源的一个开源协作平台。 Mattermost存在授权问题漏洞,该漏洞源于未在用户账户停用时失效OAuth刷新令牌,导致被停用的用户或持有有效刷新令牌的攻击者可通过OAuth刷新令牌授权端点获取新的功能访问令牌。以下版本受到影响:11.7.2及之前的11.7.x版本、11.6.4及之前的11.6.x版本和10.11.19及之前的10.11.x版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
MattermostMattermost 11.7.0 ~ 11.7.2 -

II. Public POCs for CVE-2026-9571

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9571

登录查看更多情报信息。

Same Patch Batch · Mattermost · 2026-07-13 · 10 CVEs total

CVE-2026-68506.5 MEDIUMCrafted message attachment causes client-side denial of service via markdown parser regex
CVE-2026-101066.5 MEDIUMUnauthorized users can trigger interactive post actions in private channels via action coo
CVE-2026-95975.4 MEDIUMDeactivated guest accounts can authenticate via magic-link token in Mattermost REST API lo
CVE-2026-100855.4 MEDIUMOrdinary group/direct message member can enable group_constrained and remove all channel p
CVE-2026-97084.9 MEDIUMIncoming webhook user attribution via unvalidated webhook owner
CVE-2026-65414.3 MEDIUMUnscoped updates to other playbooks' metric configuration
CVE-2026-98244.3 MEDIUMRemote cluster metadata enumeration via /share-channel autocomplete
CVE-2026-101034.3 MEDIUMAuthenticated remote cluster can modify or delete posts it does not own in Mattermost Conn
CVE-2026-98203.8 LOWMattermost schemes teams endpoint exposes private team invite IDs

IV. Related Vulnerabilities

V. Comments for CVE-2026-9571

No comments yet


Leave a comment