
CVE-2026-3590 Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, … https://www.cve.org/CVERecord?id=CVE-2026-3590
Post summary
The text lists affected Mattermost versions and the flaw that tokens are not enforced as single-use, but it does not provide a PoC, exploit, patch, or evidence of active exploitation.

