Medium severity4.2NVD Advisory· Published Jun 25, 2026· Updated Aug 11, 2026
CVE-2026-2299
CVE-2026-2299
Description
The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership.
Affected products
4cpe:2.3:a:mattermost:google_drive:*:*:*:*:*:mattermost:*:*+ 2 more
- cpe:2.3:a:mattermost:google_drive:*:*:*:*:*:mattermost:*:*range: <1.1.0
- cpe:2.3:a:mattermost:google_drive:1.1.0:rc1:*:*:*:mattermost:*:*
- cpe:2.3:a:mattermost:google_drive:1.1.0:rc2:*:*:*:mattermost:*:*
- Range: <1.1.0
Patches
Vulnerability mechanics
References
1- github.com/mattermost/mattermost-plugin-google-drive/releases/tag/v1.1.0nvdProductRelease Notes
News mentions
0No linked articles in our index yet.