Mattermost <=11.3.0 RCE via plugin install on CI test with default admin creds
CVE-2026-2462 Published on March 16, 2026
Admin RCE via Malicious Plugin Upload on CI Test Instances
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528
Vulnerability Analysis
CVE-2026-2462 is exploitable with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be low. considered to have a small impact on confidentiality and integrity and availability.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-2462 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-2462
Want to know whenever a new CVE is published for MatterMost? stack.watch will email you.
Affected Versions
Mattermost:- Version 11.3.0, <= 11.3.0 is affected.
- Version 11.2.0, <= 11.2.2 is affected.
- Version 10.11.0, <= 10.11.10 is affected.
- Version 11.4.0 is unaffected.
- Version 11.3.1 is unaffected.
- Version 11.2.3 is unaffected.
- Version 10.11.11 is unaffected.