What is CVE-2026-16045?
A critical flaw has been discovered in the Mattermost platform. In affected versions, an OAuth app with a delegated user token can bypass direct user session restrictions to access deauthorization and personal access token management endpoints, allowing unauthorized revocation of the user’s permissions and tokens for other integrations. Organizations using versions up to 11.7.6 and 10.11.21 must apply patches immediately.
Azərbaycanca: Mattermost platformasında kritik bir qüsur aşkarlanıb. Təsirə məruz qalan versiyalarda OAuth tətbiqləri, birbaşa istifadəçi sessiyası olmadan deauthorization və personal access token idarəetməsi əməliyyatlarını icra edə bilir, bu da istifadəçi icazələrinin və digər inteqrasiya tokenlərinin icazəsiz ləğvinə səbəb olur. 11.7.6 və 10.11.21 daxil olmaqla bu versiyaları istifadə edən təşkilatlar dərhal yamaları tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What unauthorized operations does the critical flaw in the Mattermost platform allow?
The CVE-2026-16045 vulnerability allows OAuth apps to perform deauthorization and personal access token management operations without a direct user session, enabling unauthorized revocation of the user's permissions and tokens for other integrations.
To which Mattermost versions must organizations apply patches to address CVE-2026-16045?
Organizations must immediately apply patches to affected Mattermost versions, including those up to 11.7.6 and 10.11.21.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.