A vulnerability, which was classified as problematic, has been found in Mattermost up to 10.11.21/11.7.6. This impacts an unknown function of the component OAuth Token Management. The manipulation leads to improper authorization.
This vulnerability is documented as CVE-2026-16045. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.