Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint
Vulnerability Description
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
使用基本弱点进行的认证绕过
Vulnerability Title
Mattermost 授权问题漏洞
Vulnerability Description
Mattermost是美国Mattermost公司开源的一个开源协作平台。 Mattermost 11.7.2及之前的11.7.x版本和11.6.4及之前的11.6.x版本存在授权问题漏洞,该漏洞源于在魔法链接令牌登录路径中未能验证来宾账户是否已被停用,允许已停用的来宾用户通过停用前签发的魔法链接令牌获取完全有效的会话。
CVSS Information
N/A
Vulnerability Type
N/A