Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost Google Drive plugin to version 1.1.0 or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 26 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Google Drive Plugin |
|
| Vendors & Products |
Mattermost
Mattermost mattermost Google Drive Plugin |
Thu, 25 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership. | |
| Title | Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-06-26T14:05:09.476Z
Reserved: 2026-02-10T16:46:56.322Z
Link: CVE-2026-2299
Updated: 2026-06-26T14:05:02.576Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T09:36:28Z