CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-16049

mediumCVSS 4.3covered by 1 sourcefirst seen 2026-08-17
Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails to validate the_ {{web_url}} _parameter against the configured GitLab instance, which allows an authenticated attacker to inject bot-authored messages containing arbitrary URLs into channels they do not have access to via the_ {{createIssue}} _and_ {{attachCommentToIssue}} _API endpoints._ Mattermost Advisory ID: MMSA-2026-00673

⚡ Watch CVE-2026-16049

Get an email if CVE-2026-16049 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-16049

CVE.org record

Embed the live status

CVE-2026-16049 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-16049 status](https://www.csirts.com/badge/CVE-2026-16049)](https://www.csirts.com/cve/CVE-2026-16049)