Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost Mobile Apps to versions 2.38.0, 11.5.0, 2.37.1.0, 11.4.1, 11.3.2, 11.2.4, 10.11.12 or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Thu, 21 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Thu, 21 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credentials for a legitimate Mattermost server via relaying the SSO code exchange flow through the mobile application. Mattermost Advisory ID: MMSA-2025-00564 | |
| Title | Mobile SSO authentication flow allows credential theft via malicious server | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-05-21T12:39:30.334Z
Reserved: 2026-02-23T22:07:32.793Z
Link: CVE-2026-22880
Updated: 2026-05-21T12:39:16.976Z
Status : Awaiting Analysis
Published: 2026-05-21T09:16:26.510
Modified: 2026-06-17T10:20:33.273
Link: CVE-2026-22880
No data.
OpenCVE Enrichment
Updated: 2026-05-21T10:30:08Z