Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-0260

NIXPKGS-2026-0260
published on
Permalink CVE-2026-0999
5.4 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
updated 1 month, 4 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse ignored
    4 packages
    • mattermost-desktop
    • python312Packages.mattermostdriver
    • python313Packages.mattermostdriver
    • python314Packages.mattermostdriver
  • @LeSuisse deleted
    5 maintainers
    • @ryantm
    • @mgdelacroix
    • @numinit
    • @Kranzes
    • @fsagbuya
    maintainer.delete
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
Authentication bypass via userID login when email and username login are disabled

Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-only login requirements via userID-based authentication. Mattermost Advisory ID: MMSA-2025-00548

References

Affected products

Mattermost
  • ==11.2.2
  • =<11.1.2
  • =<11.2.1
  • ==11.1.3
  • ==10.11.10
  • ==11.3.0
  • =<10.11.9

Matching in nixpkgs

pkgs.mattermostLatest

Mattermost is an open source platform for secure collaboration across the entire software development lifecycle

Ignored packages (4)

Package maintainers

Ignored maintainers (5)
Fixed in:
* Unstable: https://github.com/NixOS/nixpkgs/pull/480349 / https://github.com/NixOS/nixpkgs/pull/478724
* 25.11: https://github.com/NixOS/nixpkgs/pull/480574 / https://github.com/NixOS/nixpkgs/pull/479561