CVE-2026-12985
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a remote unauthenticated attacker to register an OAuth client with an attacker-controlled callback host that bypasses the configured redirect URI allowlist via a crafted redirect URI that places an allowlisted host/path suffix inside the query string.. Mattermost Advisory ID: MMSA-2026-00700
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- EPSS probability
- 0.28%
- CWE
- CWE-601
- Published
- 2026-09-14
- Last modified
- 2026-09-15
Affected products
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
- Mattermost Mattermost
Weakness type
Related vulnerabilities
- CVE-2026-6795 — Open Redirect in DivvyDrive Information Technologies' DivvyDrive
- CVE-2026-54588 — Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.
- CVE-2026-53662 — immich: One-click account takeover via XSS in login page continue redirect
- CVE-2026-43941 — Unvalidated shell.openExternal in electerm allows arbitrary protocol execution via terminal link click
- CVE-2026-61451 — Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url
- CVE-2026-8323 — Open Redirect in Armiya Information Technologies' Access Control System
- CVE-2026-71428 — unstructured: Server-Side Request Forgery in the URL-based partitioning
- CVE-2026-54072 — Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL