Medium severity5.4NVD Advisory· Published May 22, 2026· Updated Jul 23, 2026
CVE-2026-28735
CVE-2026-28735
Description
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying the scope parameter in the GitHub authorization URL.. Mattermost Advisory ID: MMSA-2026-00628
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/mattermost/mattermost-serverGo | >= 11.6.0, < 11.6.1 | 11.6.1 |
github.com/mattermost/mattermost-serverGo | >= 11.5.0, < 11.5.4 | 11.5.4 |
github.com/mattermost/mattermost-serverGo | >= 11.4.0, < 11.4.5 | 11.4.5 |
github.com/mattermost/mattermost-serverGo | >= 10.11.0, < 10.11.15 | 10.11.15 |
github.com/mattermost/mattermost-plugin-githubGo | < 1.0.1-0.20260318132218-6e6b740c4852 | 1.0.1-0.20260318132218-6e6b740c4852 |
Affected products
3cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*range: >=10.11.0,<10.11.15
- (no CPE)range: <=11.6.0, <=11.5.3, <=11.4.4, <=10.11.14
- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-r5vf-grcx-5vqpghsaADVISORY
- mattermost.com/security-updatesnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-28735ghsaADVISORY
- github.com/mattermost/mattermost-plugin-github/commit/6e6b740c4852cdfa136ee0ced160da832285c353ghsaWEB
News mentions
0No linked articles in our index yet.