PT-2026-52566 · Mattermost · Google Drive Plugin

·

CVE-2026-2299

·

Published

2026-06-25

·

Updated

2026-08-11

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mattermost Google Drive plugin versions prior to 1.1.0
Description An improper access control issue exists where the plugin fails to validate channel membership in the file creation endpoint. This allows authenticated users with a connected Google account to share Google Drive files to private channels they are not members of, which also leads to the disclosure of private channel membership.
Recommendations Update Mattermost Google Drive plugin to version 1.1.0 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2299

Affected Products

Google Drive Plugin