Mattermost OAuth Client Identity Binding Vulnerability in Authorization Code Redemption Flow

Vulnerability

A vulnerability exists in Mattermost versions 11.5.x through 11.5.1 and 10.11.x through 10.11.13, where the application fails to properly enforce client identity binding during the OAuth authorization code redemption process. This flaw allows an authenticated OAuth client to misuse authorization codes intended for a different client by sending a manipulated token exchange request.

Impact

Exploitation of this vulnerability could lead to unauthorized access to resources or actions on behalf of the affected client, by allowing the interception and misuse of authorization codes.

Remediation

Users can upgrade to Mattermost versions 11.7.0 or 11.4.15 to address this vulnerability.

Added: May 18, 2026, 8:20 AM
Updated: May 18, 2026, 8:20 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
1.3
exploitability
4.7
remediation
7.7
relevance
8.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.