External risk intelligence

Mattermost OAuth Client Registration URI Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-12985

Mattermost is a collaboration platform typically deployed as an internet-facing web application. Since this vulnerability affects the OAuth dynamic client registration process, which is a common feature exposed to users and integrated services on web-facing instances, it is likely to be reachable from the internet in common deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Mattermost's handling of redirect URIs for OAuth client registration. An unauthenticated attacker could exploit this by registering an OAuth client with a malicious callback host, potentially bypassing security controls and leading to unauthorized access or data exposure. The main concern is confirming relevance and exposure of Mattermost instances.

  • Flaw allows unauthenticated callback host registration.
  • Bypasses allowlist for OAuth client registration.
  • Confirm relevance and exposure of Mattermost.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by registering a malicious OAuth client. This is possible because the system improperly validates redirect URIs when registering OAuth clients. An attacker could craft a redirect URI to bypass allowlists, leading to a callback to an attacker-controlled host.

  • Unauthenticated remote attacker.
  • Registering a malicious OAuth client.
  • Redirect URI bypass allows callback.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to register an OAuth client with a malicious callback host, bypassing security controls when specific redirect URI patterns are used. This could potentially expose sensitive information or allow unauthorized actions when supported by the advisory.

  • OAuth client registration.
  • Crafted redirect URI bypasses allowlist.
  • Unauthorized access or data exposure.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Mattermost server instances and requires action from teams responsible for its operation and security. The immediate first step is to inventory all Mattermost deployments, assess their exposure and business criticality, and identify the accountable system owner for each instance. Remediation planning should then be prioritized based on this risk assessment.

  • Identify Mattermost instances and owners.
  • Verify reachability and business criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Mattermost Server?

Mattermost is an open-source collaboration platform designed for secure team communication. It functions as a self-hosted or cloud-based workspace where users share messages, files, and integrate various third-party tools. Organizations use it to centralize internal workflows and maintain control over their data.

What does CWE-601 mean for CVE-2026-12985?

CWE-601 refers to URL Redirection to Untrusted Site, often called an Open Redirect. In this CVE, the vulnerability allows an attacker to manipulate the OAuth client registration process. Because the software validates redirect locations incorrectly, an attacker can trick the system into trusting a malicious address, effectively bypassing the security rules meant to keep OAuth traffic within safe, approved domains.

How can an attacker trigger this vulnerability?

An attacker triggers this by submitting a specially crafted redirect URI during the OAuth client registration process. The software incorrectly matches this URI against its allowlist using raw string patterns rather than proper URL components. Importantly, simply visiting the site does not trigger this; the bug requires the attacker to actively register a malicious client using a bypass technique that hides their callback host within the URI's query string.

Do I need to worry if my Mattermost instance is internal?

According to Halo Surface Signal, you should prioritize this if your instance is internet-facing, as that is the common deployment model for OAuth-enabled collaboration tools. While internal-only instances face less direct risk from external actors, the vulnerability remains a concern if your Mattermost server is reachable or integrated with services that are accessible from less trusted network zones.

Is there a first step for managing this CVE?

Your first step is to inventory all active Mattermost installations within your environment to determine which versions are running. Once you have a complete list, verify the network reachability of each instance and identify the team responsible for maintenance. This baseline allows you to prioritize patching efforts based on which servers are most critical or exposed to external traffic.

References