CVE-2026-27656

Account Takeover via Substring Matching in OpenID Connect Authentication

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts via an overly permissive substring matching flaw in the user discovery flow.. Mattermost Advisory ID: MMSA-2026-00590


We have discovered 174 live websites that are affected by CVE-2026-27656.

Run a Free Instant Scan




Affected Software

Product  Mattermost
Category Message Boards
Vulnerable Domains174 live websites (42% of Mattermost install base)
Vulnerable Versions
  • from 10.11 through 10.11.11
  • from 11.2 through 11.2.3
  • from 11.3 through 11.3.1
  • from 11.4 through 11.4
Vulnerable Versions Count14 versions ( 21% of all versions)


Common Weakness Enumeration

CWE-303 Incorrect Implementation of Authentication Algorithm



Details

  • Published - Mar 25, 2026
  • Updated - Mar 26, 2026

Credits

  • Christopher Poile (finder)

Website Distribution by Country

Number of websites using CVE-2026-27656
United States35 websites



Germany46 websites
France22 websites
Singapore20 websites
GB8 websites
Russia7 websites
Canada6 websites
Netherlands4 websites
Switzerland2 websites

Website Distribution by TLD

Number of websites using CVE-2026-27656
.com47 websites
.de24 websites
.org21 websites
.fr12 websites
.net9 websites
.ru6 websites
.ca4 websites
.nl3 websites
.co.uk3 websites
.co2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-27656

Top websites that are affected by CVE-2026-27656. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com Germany***,***
****.*******.com GB***,***
**********.*********.org France***,***
************.com United States*,***,***
**.*****.re Germany*,***,***
**********.*********.org France*,***,***
****.*******.com Germany*,***,***
**********.*****.at Austria*,***,***
***********.com Singapore*,***,***
***************.no Germany*,***,***
See full domain list

FAQ

CVE-2026-27656 is Incorrect Implementation of Authentication Algorithm in Mattermost
A total of 174 websites have been identified as vulnerable to CVE-2026-27656, based on global website indexing conducted by WebTechSurvey.
The Mattermost is affected by the CVE-2026-27656 vulnerability.
Mattermost versions up to and including 11.4 are vulnerable to CVE-2026-27656.