Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts via an overly permissive substring matching flaw in the user discovery flow.. Mattermost Advisory ID: MMSA-2026-00590
We have discovered 174 live websites that are affected by CVE-2026-27656.
| Product | |
| Category | Message Boards |
| Vulnerable Domains | 174 live websites (42% of Mattermost install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 14 versions ( 21% of all versions) |
| 35 websites | |
| 46 websites | |
| 22 websites | |
| 20 websites | |
| 8 websites | |
| 7 websites | |
| 6 websites | |
| 4 websites | |
| 2 websites |
| .com | 47 websites |
| .de | 24 websites |
| .org | 21 websites |
| .fr | 12 websites |
| .net | 9 websites |
| .ru | 6 websites |
| .ca | 4 websites |
| .nl | 3 websites |
| .co.uk | 3 websites |
| .co | 2 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | ***,*** | ||
| ****.*******.com | ***,*** | ||
| **********.*********.org | ***,*** | ||
| ************.com | *,***,*** | ||
| **.*****.re | *,***,*** | ||
| **********.*********.org | *,***,*** | ||
| ****.*******.com | *,***,*** | ||
| **********.*****.at | *,***,*** | ||
| ***********.com | *,***,*** | ||
| ***************.no | *,***,*** |
FAQ