Mattermost
Mattermost Server: vulnerabilidades y CVE
Mattermost Server tiene 467 vulnerabilidades publicadas, 144 de ellas en los últimos 12 meses. 16 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE467
Últimos 12 meses144
Críticas16
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-9693 | Baja (3.5) | 0.27% | — | 17 ago 2026 | Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited… |
| CVE-2026-9859 | Media (6.5) | 0.34% | — | 17 ago 2026 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink… |
| CVE-2026-9816 | Alta (8.3) | 0.35% | — | 17 ago 2026 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member… |
| CVE-2026-10080 | Media (6.5) | 0.42% | — | 17 ago 2026 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authenticated user to crash the plugin process and deny service to all Boards… |
| CVE-2026-16048 | Media (6.3) | 0.26% | — | 17 ago 2026 | Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel… |
| CVE-2026-16047 | Media (4.3) | 0.27% | — | 17 ago 2026 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that users have read access to a channel before linking a board to it, which allows an authenticated attacker to discover the… |
| CVE-2026-16046 | Media (4.3) | 0.25% | — | 17 ago 2026 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for finished playbook runs which allows a run participant to modify status, checklists, retrospective… |
| CVE-2026-16045 | Media (4.3) | 0.33% | — | 17 ago 2026 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and personal access token management endpoints to direct user sessions, which allowed an OAuth app with a… |
| CVE-2026-16044 | Media (5.4) | 0.29% | — | 17 ago 2026 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive import which allows a board member to escalate a guest user to Board Admin… |
| CVE-2026-15754 | Media (4.2) | 0.25% | — | 17 ago 2026 | Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate that each target channel still belongs to the requesting admin's team, which allows an… |
| CVE-2026-10527 | Media (6.3) | 0.26% | — | 17 ago 2026 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which allows a user demoted to System Guest to retain Board Admin privileges… |
| CVE-2026-14298 | Media (6.5) | 0.42% | — | 13 ago 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler,… |
| CVE-2026-7521 | Media (5.5) | 0.44% | — | 28 jul 2026 | Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files… |
| CVE-2026-10819 | Media (6.5) | 0.42% | — | 27 jul 2026 | Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated… |
| CVE-2026-10600 | Media (4.3) | 0.37% | — | 27 jul 2026 | Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user… |
| CVE-2026-9824 | Media (4.3) | 0.27% | — | 13 jul 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that… |
| CVE-2026-9820 | Baja (3.8) | 0.26% | — | 13 jul 2026 | Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and… |
| CVE-2026-6541 | Media (4.3) | 0.25% | — | 13 jul 2026 | Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another… |
| CVE-2026-9708 | Media (4.9) | 0.36% | — | 13 jul 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook… |
| CVE-2026-9597 | Media (5.4) | 0.23% | — | 13 jul 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain… |
| CVE-2026-9571 | Media (6.5) | 0.30% | — | 13 jul 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid… |
| CVE-2026-6850 | Media (6.5) | 0.42% | — | 13 jul 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service… |
| CVE-2026-10106 | Media (6.5) | 0.30% | — | 13 jul 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user… |
| CVE-2026-10103 | Media (4.3) | 0.24% | — | 13 jul 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows an authenticated remote cluster to modify or delete… |
| CVE-2026-10085 | Media (5.4) | 0.29% | — | 13 jul 2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary… |
| CVE-2026-4339 | Media (6.5) | 0.14% | — | 26 jun 2026 | Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with… |
| CVE-2026-3472 | Baja (3.5) | 0.27% | — | 26 jun 2026 | Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows an authenticated attacker to exfiltrate… |
| CVE-2026-8823 | Baja (3.8) | 0.32% | — | 22 jun 2026 | Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to validate bot targets when demoting users to guests which allows a lower-privileged administrator to degrade arbitrary bot accounts via the standard… |
| CVE-2026-9162 | Media (4.3) | 0.33% | — | 22 jun 2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached authentication state for active WebSocket connections during global session revocation, which… |
| CVE-2026-8074 | Baja (3.8) | 0.32% | — | 22 jun 2026 | Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a User Manager with user management write access but no… |