{"id":"CVE-2026-22880","title":"Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credenti…","summary":"Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credenti…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N","cwe":["CWE-352"],"vendor":"mattermost","product":"mattermost_mobile","affected":["mattermost_mobile < 2.37.1"],"patched":["mattermost_mobile 2.37.1"],"published":"2026-05-21","updated":"2026-08-06","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-22880","references":[{"url":"https://mattermost.com/security-updates","label":"responsibledisclosure@mattermost.com"}],"tags":["nvd"],"epss":0.00117,"epssPercentile":0.01921,"ingestedAt":"2026-08-06T16:00:00.101Z","slug":"CVE-2026-22880","body":"## Overview\n\nMattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credentials for a legitimate Mattermost server via relaying the SSO code exchange flow through the mobile application. Mattermost Advisory ID: MMSA-2025-00564\n\n## Affected\n\n- `mattermost_mobile < 2.37.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `mattermost_mobile 2.37.1`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}