---
id: CVE-2026-22880
title: >-
  Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2
  10.11.11.0 fail to properly validate the SSO authentication callback origin
  which allows an attacker controlling a malicious Mattermost server to steal
  user credenti…
summary: >-
  Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2
  10.11.11.0 fail to properly validate the SSO authentication callback origin
  which allows an attacker controlling a malicious Mattermost server to steal
  user credenti…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N'
cwe:
  - CWE-352
vendor: mattermost
product: mattermost_mobile
affected:
  - mattermost_mobile < 2.37.1
patched:
  - mattermost_mobile 2.37.1
published: '2026-05-21'
updated: '2026-08-06'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-22880'
references:
  - url: 'https://mattermost.com/security-updates'
    label: responsibledisclosure@mattermost.com
tags:
  - nvd
epss: 0.00117
epssPercentile: 0.01918
ingestedAt: '2026-08-06T16:00:00.101Z'
---

## Overview

Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credentials for a legitimate Mattermost server via relaying the SSO code exchange flow through the mobile application. Mattermost Advisory ID: MMSA-2025-00564

## Affected

- `mattermost_mobile < 2.37.1`

## Remediation

Upgrade past the affected range:

- `mattermost_mobile 2.37.1`
