What is CVE-2026-16049?
CVE-2026-16049 affects the Mattermost GitLab plugin. It fails to verify channel permissions for API requests using a caller-supplied {{post_id}} and does not validate the {{web_url}} parameter against the configured GitLab instance, allowing an authenticated user to perform unauthorized actions. Updating to the latest plugin version is recommended.
Azərbaycanca: CVE-2026-16049 Mattermost-un GitLab plaginində aşkarlanıb. Autentifikasiya olunmuş istifadəçi müəyyən API sorğularında kanal icazələrini yoxlamamaq və {{web_url}} parametrini düzgün validasiya etməmək zəifliyindən istifadə edərək icazəsiz əməliyyatlar həyata keçirə bilər. Plaginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Mattermost
FAQ2
Is authentication required to exploit CVE-2026-16049?
Yes, an authenticated user is required to exploit this vulnerability.
Which component of Mattermost is affected by CVE-2026-16049?
This vulnerability is found in the Mattermost GitLab plugin.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.