A vulnerability, which was classified as problematic, was found in Mattermost GitLab Plugin up to 10.11.20/10.20.11/11.5.7/11.7.5/11.8.x. Affected is an unknown function of the component Channel Permission. The manipulation of the argument post_id/web_url results in permission issues.
This vulnerability is reported as CVE-2026-16049. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.