Skip to main content
Vulnerability Database/CVE-2026-96259

CVE-2026-96259: Mattermost OAuth SSRF Vulnerability

CVE-2026-96259 is a server-side request forgery vulnerability in Mattermost that enables System Administrators to exploit OAuth endpoints for internal network probing. This article covers technical details, affected versions, impact analysis, and mitigation strategies.

Published:

CVE-2026-96259 Overview

CVE-2026-96259 is a Server-Side Request Forgery (SSRF) vulnerability in Mattermost affecting multiple release branches. The flaw resides in the OAuth token and userinfo endpoint request handling, where the internal-connection filter is not applied. A System Administrator can configure OAuth endpoints that point to internal network addresses, causing the Mattermost server to issue requests to those addresses and return the responses. The issue is tracked under Mattermost Advisory ID MMSA-2026-00776 and is categorized as [CWE-918].

Critical Impact

An authenticated System Administrator can pivot the Mattermost server into the internal network, reading responses from services normally unreachable from the public internet.

Affected Products

  • Mattermost 11.9.x versions up to and including 11.9.1
  • Mattermost 11.8.x versions up to and including 11.8.5, and 11.7.x versions up to and including 11.7.10
  • Mattermost 11.10.x versions up to and including 11.10.1

Discovery Timeline

  • 2026-09-22 - CVE-2026-96259 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-96259

Vulnerability Analysis

Mattermost enforces an internal-connection filter to prevent the server from initiating outbound HTTP requests to private or loopback address ranges. This filter blocks common SSRF targets such as 127.0.0.1, 169.254.169.254, and RFC1918 network ranges. The OAuth code path that fetches tokens and user information from configured OAuth providers does not apply this filter. When a System Administrator configures the OAuth token endpoint or userinfo endpoint to an internal URL, the server issues the HTTP request and returns the raw response body to the caller. The classification maps to [CWE-918] Server-Side Request Forgery.

Root Cause

The OAuth client used by Mattermost bypasses the centralized outbound-request validator that other integrations rely on. Requests originating from OAuth flows are dispatched directly through the HTTP client without first resolving the destination host and checking it against the internal-address deny list.

Attack Vector

Exploitation requires System Administrator privileges, which is reflected in the high privileges required rating. The administrator configures a malicious or attacker-controlled OAuth provider entry pointing token or userinfo URLs at internal targets such as cloud metadata services, internal admin panels, or database HTTP interfaces. When the OAuth flow triggers, Mattermost fetches the URLs and exposes the response content. The scope change indicates the attack can reach resources beyond Mattermost's own security boundary.

No public proof-of-concept code is available. See the Mattermost Security Updates page for vendor technical details.

Detection Methods for CVE-2026-96259

Indicators of Compromise

  • Mattermost server outbound HTTP requests to RFC1918 addresses, loopback, or link-local ranges such as 169.254.169.254 originating from the OAuth client code path.
  • OAuth provider configuration changes where token or userinfo endpoints reference internal hostnames or IP addresses.
  • Unexpected responses returned to administrator sessions during OAuth configuration testing.

Detection Strategies

  • Monitor Mattermost audit logs for configuration updates to ServiceSettings OAuth provider entries, particularly changes to TokenEndpoint and UserAPIEndpoint values.
  • Inspect egress network telemetry for connections from the Mattermost process to internal ranges that should never be contacted by a chat server.
  • Correlate administrator login events with subsequent OAuth configuration modifications and outbound request spikes.

Monitoring Recommendations

  • Alert when the Mattermost server initiates connections to cloud instance metadata endpoints such as 169.254.169.254 or metadata.google.internal.
  • Baseline the set of external OAuth providers used in production and flag deviations.
  • Retain HTTP proxy logs for outbound Mattermost traffic to support post-incident review.

How to Mitigate CVE-2026-96259

Immediate Actions Required

  • Upgrade Mattermost to a version above the affected ranges: later than 11.9.1, 11.8.5, 11.7.10, or 11.10.1 depending on the deployed branch.
  • Audit existing OAuth provider configurations and remove any entries referencing internal hostnames or IP addresses.
  • Review the System Administrator role membership and revoke access for accounts that do not require it.

Patch Information

Mattermost has published fixes as documented in advisory MMSA-2026-00776. Consult the Mattermost Security Updates page for the specific fixed build numbers and release notes.

Workarounds

  • Place the Mattermost server behind an egress proxy that denies traffic to internal IP ranges and cloud metadata endpoints.
  • Apply network segmentation so the Mattermost host cannot route to sensitive internal services or metadata APIs.
  • Restrict System Administrator access through strong authentication and just-in-time privilege elevation until patching is complete.
bash
# Example egress restriction using iptables to block metadata and RFC1918 targets
iptables -A OUTPUT -m owner --uid-owner mattermost -d 169.254.169.254 -j REJECT
iptables -A OUTPUT -m owner --uid-owner mattermost -d 10.0.0.0/8 -j REJECT
iptables -A OUTPUT -m owner --uid-owner mattermost -d 172.16.0.0/12 -j REJECT
iptables -A OUTPUT -m owner --uid-owner mattermost -d 192.168.0.0/16 -j REJECT

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.