Mattermost · Mattermost · CVE-2026-12985
**Name of the Vulnerable Software and Affected Versions**
Mattermost version 11.9.0
Mattermost versions 11.8.0 through 11.8.4
Mattermost versions 11.7.0 through 11.7.7
**Description**
An issue exists where the software fails to validate Dynamic Client Registration redirect URIs by URL component, instead matching glob patterns against the raw URI string. This allows a remote unauthenticated attacker to register an OAuth client with a callback host under their control. The attacker can bypass the configured redirect URI allowlist by using a crafted redirect URI that places an allowlisted host or path suffix within the query string.
**Recommendations**
Update Mattermost version 11.9.0 to a newer version.
Update Mattermost versions 11.8.0 through 11.8.4 to a newer version.
Update Mattermost versions 11.7.0 through 11.7.7 to a newer version.