Generated remediation guidance and an executive summary. No account required.
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost Advisory ID: MMSA-2025-00528
Cite this page
CVE-2026-2462. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-2462
Use CWE-863, Mattermost vendor hub and Mattermost Server product page to widen CVE-2026-2462 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-3108, CVE-2026-28741 and CVE-2026-3112 for nearby disclosures in the same product family.