CVE-2026-96259 Overview
CVE-2026-96259 is a Server-Side Request Forgery (SSRF) vulnerability in Mattermost affecting multiple release branches. The flaw resides in the OAuth token and userinfo endpoint request handling, where the internal-connection filter is not applied. A System Administrator can configure OAuth endpoints that point to internal network addresses, causing the Mattermost server to issue requests to those addresses and return the responses. The issue is tracked under Mattermost Advisory ID MMSA-2026-00776 and is categorized as [CWE-918].
Critical Impact
An authenticated System Administrator can pivot the Mattermost server into the internal network, reading responses from services normally unreachable from the public internet.
Affected Products
- Mattermost 11.9.x versions up to and including 11.9.1
- Mattermost 11.8.x versions up to and including 11.8.5, and 11.7.x versions up to and including 11.7.10
- Mattermost 11.10.x versions up to and including 11.10.1
Discovery Timeline
- 2026-09-22 - CVE-2026-96259 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-96259
Vulnerability Analysis
Mattermost enforces an internal-connection filter to prevent the server from initiating outbound HTTP requests to private or loopback address ranges. This filter blocks common SSRF targets such as 127.0.0.1, 169.254.169.254, and RFC1918 network ranges. The OAuth code path that fetches tokens and user information from configured OAuth providers does not apply this filter. When a System Administrator configures the OAuth token endpoint or userinfo endpoint to an internal URL, the server issues the HTTP request and returns the raw response body to the caller. The classification maps to [CWE-918] Server-Side Request Forgery.
Root Cause
The OAuth client used by Mattermost bypasses the centralized outbound-request validator that other integrations rely on. Requests originating from OAuth flows are dispatched directly through the HTTP client without first resolving the destination host and checking it against the internal-address deny list.
Attack Vector
Exploitation requires System Administrator privileges, which is reflected in the high privileges required rating. The administrator configures a malicious or attacker-controlled OAuth provider entry pointing token or userinfo URLs at internal targets such as cloud metadata services, internal admin panels, or database HTTP interfaces. When the OAuth flow triggers, Mattermost fetches the URLs and exposes the response content. The scope change indicates the attack can reach resources beyond Mattermost's own security boundary.
No public proof-of-concept code is available. See the Mattermost Security Updates page for vendor technical details.
Detection Methods for CVE-2026-96259
Indicators of Compromise
- Mattermost server outbound HTTP requests to RFC1918 addresses, loopback, or link-local ranges such as 169.254.169.254 originating from the OAuth client code path.
- OAuth provider configuration changes where token or userinfo endpoints reference internal hostnames or IP addresses.
- Unexpected responses returned to administrator sessions during OAuth configuration testing.
Detection Strategies
- Monitor Mattermost audit logs for configuration updates to ServiceSettings OAuth provider entries, particularly changes to TokenEndpoint and UserAPIEndpoint values.
- Inspect egress network telemetry for connections from the Mattermost process to internal ranges that should never be contacted by a chat server.
- Correlate administrator login events with subsequent OAuth configuration modifications and outbound request spikes.
Monitoring Recommendations
- Alert when the Mattermost server initiates connections to cloud instance metadata endpoints such as 169.254.169.254 or metadata.google.internal.
- Baseline the set of external OAuth providers used in production and flag deviations.
- Retain HTTP proxy logs for outbound Mattermost traffic to support post-incident review.
How to Mitigate CVE-2026-96259
Immediate Actions Required
- Upgrade Mattermost to a version above the affected ranges: later than 11.9.1, 11.8.5, 11.7.10, or 11.10.1 depending on the deployed branch.
- Audit existing OAuth provider configurations and remove any entries referencing internal hostnames or IP addresses.
- Review the System Administrator role membership and revoke access for accounts that do not require it.
Patch Information
Mattermost has published fixes as documented in advisory MMSA-2026-00776. Consult the Mattermost Security Updates page for the specific fixed build numbers and release notes.
Workarounds
- Place the Mattermost server behind an egress proxy that denies traffic to internal IP ranges and cloud metadata endpoints.
- Apply network segmentation so the Mattermost host cannot route to sensitive internal services or metadata APIs.
- Restrict System Administrator access through strong authentication and just-in-time privilege elevation until patching is complete.
# Example egress restriction using iptables to block metadata and RFC1918 targets
iptables -A OUTPUT -m owner --uid-owner mattermost -d 169.254.169.254 -j REJECT
iptables -A OUTPUT -m owner --uid-owner mattermost -d 10.0.0.0/8 -j REJECT
iptables -A OUTPUT -m owner --uid-owner mattermost -d 172.16.0.0/12 -j REJECT
iptables -A OUTPUT -m owner --uid-owner mattermost -d 192.168.0.0/16 -j REJECT
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.