CVE-2026-28732

MEDIUM

Mattermost 10.11.0-10.11.13 11.4.0-11.4.3 11.5.0-11.5.1 - Slash Command Hijacking via Trigger-Word Bypass

Title source: llm
STIX 2.1

Description

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom slash commands via editing their own slash command trigger to an already-registered trigger through the command update API. Mattermost Advisory ID: MMSA-2026-00597

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
MMSA-2026-00597
https://mattermost.com/security-updates

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 9.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (8)
Mattermost/Mattermost 10.11.0 - 10.11.13
Mattermost/Mattermost 10.11.14
Mattermost/Mattermost 11.4.0 - 11.4.3
Mattermost/Mattermost 11.4.4
Mattermost/Mattermost 11.5.0 - 11.5.1
Mattermost/Mattermost 11.5.2
Mattermost/Mattermost 11.6.0
mattermost/mattermost_server 10.11.0 - 10.11.14
Published May 18, 2026
Tracked Since May 18, 2026