CVE-2026-27659
MEDIUM4.6EPSS 0.03%Mattermost doesn't properly validate CSRF tokens
發布日:2026/3/25修改日:2026/3/31
描述
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to properly validate CSRF tokens in the /api/v4/access_control_policies/{policy_id}/activate endpoint, which allows an attacker to trick an admin into changing access control policy active status via a crafted request. Mattermost Advisory ID: MMSA-2026-00578
受影響套件(1)
- Go/github.com/mattermost/mattermost/server/v8>= 11.4.0-rc1, < 11.4.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N |