The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update Mattermost Google Drive plugin to version 1.1.0 or higher.
Workaround
No workaround given by the vendor.
References
History
Thu, 25 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership. | |
| Title | Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-06-25T18:55:11.905Z
Reserved: 2026-02-10T16:46:56.322Z
Link: CVE-2026-2299
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-25T21:30:11Z
Weaknesses