CVE-2026-2299

Source
https://cve.org/CVERecord?id=CVE-2026-2299
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2299.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-2299
Published
2026-06-25T18:55:11Z
Modified
2026-08-13T04:02:15Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint
Details

The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership.

Database specific
{
    "cna_assigner": "Mattermost",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2299.json"
}
References

Affected packages

Git / github.com/mattermost/mattermost-plugin-google-drive

Affected ranges

Type
GIT
Repo
https://github.com/mattermost/mattermost-plugin-google-drive
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Last Affected
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:mattermost:google_drive:*:*:*:*:*:mattermost:*:*",
        "cpe:2.3:a:mattermost:google_drive:1.1.0:rc1:*:*:*:mattermost:*:*",
        "cpe:2.3:a:mattermost:google_drive:1.1.0:rc2:*:*:*:mattermost:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.1.0"
        },
        {
            "introduced": "1.1.0-rc1"
        },
        {
            "last_affected": "1.1.0-rc1"
        },
        {
            "introduced": "1.1.0-rc2"
        },
        {
            "last_affected": "1.1.0-rc2"
        }
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.1.0-rc1
1.1.0-rc2
v1.*
v1.1.0
v1.1.0-rc1
v1.1.0-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2299.json"