CVE-2026-22880: Mobile SSO authentication flow allows credential theft via malicious server
Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credentials for a legitimate Mattermost server via relaying the SSO code exchange flow through the mobile application. Mattermost Advisory ID: MMSA-2025-00564
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22880?
The severity of CVE-2026-22880 is medium, rated at 6.1.
How do I fix CVE-2026-22880?
To fix CVE-2026-22880, update to Mattermost Mobile Apps versions 2.38.0, 11.5.0, or higher.
What does CVE-2026-22880 exploit?
CVE-2026-22880 exploits the authentication flow which fails to properly validate the SSO authentication callback origin.
Which versions of Mattermost Mobile Apps are affected by CVE-2026-22880?
Mattermost Mobile Apps versions <=2.37, 11.4, 2.0.37, 11.0.4, 11.1.3, 11.3.2, and 10.11.11.0 are affected by CVE-2026-22880.
What type of vulnerability is CVE-2026-22880 categorized as?
CVE-2026-22880 is categorized as a CSRF vulnerability.