Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost Plugins to versions 11.5.0, 10.11.12 or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Fri, 27 Mar 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Thu, 26 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to corrupt Zoom meeting state in Mattermost via replayed webhook requests. Mattermost Advisory ID: MMSA-2026-00584 | |
| Title | Missing timestamp validation in Zoom webhook handler | |
| Weaknesses | CWE-754 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-03-26T19:52:11.107Z
Reserved: 2026-02-24T10:53:41.124Z
Link: CVE-2026-3109
Updated: 2026-03-26T19:50:43.961Z
Status : Undergoing Analysis
Published: 2026-03-26T17:16:41.967
Modified: 2026-03-30T13:26:50.827
Link: CVE-2026-3109
No data.
OpenCVE Enrichment
Updated: 2026-03-27T09:26:19Z