CVE-2026-3109 - Missing timestamp validation in Zoom webhook handler
CVE ID :CVE-2026-3109
Published : March 26, 2026, 5:16 p.m. | 1 hour, 46 minutes ago
Description :Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to corrupt Zoom meeting state in Mattermost via replayed webhook requests. Mattermost Advisory ID: MMSA-2026-00584
Severity: 2.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 26, 2026, 5:16 p.m. | 1 hour, 46 minutes ago
Description :Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to corrupt Zoom meeting state in Mattermost via replayed webhook requests. Mattermost Advisory ID: MMSA-2026-00584
Severity: 2.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...