4.3

CVE-2026-2299

Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint

The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mattermost ≫ Google Drive SwPlatform mattermost Version < 1.1.0
Mattermost ≫ Google Drive Version 1.1.0 Update rc1 SwPlatform mattermost
Mattermost ≫ Google Drive Version 1.1.0 Update rc2 SwPlatform mattermost
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.022
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
responsibledisclosure@mattermost.com 4.2 1.6 2.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://github.com/mattermost/mattermost-plugin-google-drive/releases/tag/v1.1.0
Product
Release Notes