Unrated severityNVD Advisory· Published Mar 26, 2026· Updated Mar 26, 2026
Missing timestamp validation in Zoom webhook handler
CVE-2026-3109
Description
Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to corrupt Zoom meeting state in Mattermost via replayed webhook requests. Mattermost Advisory ID: MMSA-2026-00584
Affected products
1- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- mattermost.com/security-updatesmitrevendor-advisory
News mentions
1- When DNSSEC goes wrong: how we responded to the .de TLD outageCloudflare Blog · May 6, 2026