CVE-2026-27769
Connected Workspaces: Malicious remote server can manipulate arbitrary user's status
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 2.7EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
15 Apr 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed status of local users via the Connected Workspaces API.. Mattermost Advisory ID: MMSA-2026-00603
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Affected products
Mattermost · MattermostWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://mattermost.com/security-updates