CVE-2026-2299EPSS p2.1%

CVE-2026-2299CVE-2026-2299

mattermost / google_drive

Description

The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership.

Scoring

CVSS 4.2 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS0.12% probability of exploitation · percentile 2.1% · 2026-08-10T12:02:48Z
Last modified2026-08-11
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.