Mattermost Token Reuse Vulnerability in Remote Cluster Invite Confirmation

Vulnerability

A vulnerability exists in Mattermost versions 11.5.x through 11.5.1 and 10.11.x through 10.11.13, where the application fails to properly validate that the RefreshedToken is different from the original invite token during the remote cluster invite confirmation process. This flaw allows an authenticated attacker to bypass the token rotation mechanism and reuse the original invite token by sending a crafted invite confirmation that includes a RefreshedToken matching the original token.

Impact

Exploitation of this vulnerability allows for the unauthorized reuse of invite tokens, potentially leading to unauthorized access or actions within the Mattermost application.

Remediation

Users can upgrade to Mattermost versions 11.7.0 or 11.6.1 to address this vulnerability.

Added: May 18, 2026, 8:21 AM
Updated: May 18, 2026, 8:21 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
5.2
remediation
7.7
relevance
8.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.