<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Mattermost</title>
  <link>https://cvedaily.com/pages/tags/mattermost.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/mattermost.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Mattermost</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:42 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-6957 – Mattermost Plugins versions &lt;=1.1.5 fail to sanitize filenames received from fed...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6957</guid>
    <pubDate>Wed, 27 May 2026 15:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6957</strong></p>
  <p>Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destination paths, which allows an administrator of a remote federated Mattermost server to write files to arbitrary locations within the target server's filestore via a malicious filename delivered through the shared-channel attachment sync protocol. Mattermost Advis…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4915 – Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.3, 11.4.x &lt;= 11.4.4, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4915</guid>
    <pubDate>Mon, 25 May 2026 08:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4915</strong></p>
  <p>Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil elements from outgoing webhook attachment payloads before processing, which allows an authenticated user to cause a denial of service (server process termination) via a crafted webhook callback response containing a null attachment entry.. Mattermost Advisory ID: MMSA-2026-00641</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-9354 – A vulnerability was detected in NousResearch hermes-agent up to 2026.4.16. The a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9354</guid>
    <pubDate>Sun, 24 May 2026 05:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-9354</strong></p>
  <p>A vulnerability was detected in NousResearch hermes-agent up to 2026.4.16. The affected element is an unknown function of the component Slack Agent/Mattermost Agent. The manipulation of the argument format_message results in escaping of output. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond i…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28735 – Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.3, 11.4.x &lt;= 11.4.4, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28735</guid>
    <pubDate>Fri, 22 May 2026 17:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28735</strong></p>
  <p>Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying the scope parameter in the GitHub authorization URL.. Mattermost Advisory ID: MMSA-2026-00628</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5755 – Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.2, 11.5.x &lt;= 11.5.3, 11.4.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5755</guid>
    <pubDate>Fri, 22 May 2026 11:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5755</strong></p>
  <p>Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the TIFF IFD offset in the image header before allocating memory, which allows authenticated users with file upload or posting permissions to cause a denial of service (server OOM) via uploading a crafted TIFF file or posting a URL that serves one.. Mattermost Advisory…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5740 – Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.3, 11.4.x &lt;= 11.4.4, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5740</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5740</guid>
    <pubDate>Fri, 22 May 2026 11:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5740</strong></p>
  <p>Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate msgpack-encoded WebSocket frames before memory allocation which allows an unauthenticated remote attacker to crash the server process and cause a full service outage for all users via a crafted binary WebSocket message sent to the public WebSocket endpoint.. Mattermost Advisory…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5740">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5308 – Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.3, 11.4.x &lt;= 11.4.4, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5308</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5308</guid>
    <pubDate>Fri, 22 May 2026 11:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5308</strong></p>
  <p>Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP endpoints which allows an attacker to cause a denial of service via crafted oversized HTTP requests.. Mattermost Advisory ID: MMSA-2026-00646</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5308">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4646 – Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.3, 11.4.x &lt;= 11.4.4, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4646</guid>
    <pubDate>Fri, 22 May 2026 11:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4646</strong></p>
  <p>Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supplied input in API request handlers which allows an authenticated attacker to crash the plugin process via a crafted HTTP request to the PR details endpoint.. Mattermost Advisory ID: MMSA-2026-00638</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4635 – Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.3, 11.4.x &lt;= 11.4.4, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4635</guid>
    <pubDate>Fri, 22 May 2026 11:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4635</strong></p>
  <p>Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channel before removing persistent notifications which allows authenticated user to crash the server via timing the creation of persistent notification message between the server deleting existing persistent notifications and archiving the channel.. Mattermost Advisory ID: MMSA-2026-0…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3636 – Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.3, 11.4.x &lt;= 11.4.4, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3636</guid>
    <pubDate>Fri, 22 May 2026 11:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3636</strong></p>
  <p>Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team member data when returned via API to users without elevated permissions which allows a user without permissions to get data about team members roles via invoking various team API endpoints.. Mattermost Advisory ID: MMSA-2026-00626</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3473 – Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.3, 11.4.x &lt;= 11.4.4, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3473</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3473</guid>
    <pubDate>Fri, 22 May 2026 11:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3473</strong></p>
  <p>Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.. Mattermost Advisory ID: MMSA-2026-00620</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3473">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4858 – Mattermost versions 11.6.x &lt;= 11.6.0, 11.5.x &lt;= 11.5.3, 11.4.x &lt;= 11.4.4, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4858</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4858</guid>
    <pubDate>Thu, 21 May 2026 09:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4858</strong></p>
  <p>Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user  to call an arbitrary API via system admin Mattermost auth token using via path traversal in integration action URL.. Mattermost Advisory ID: MMSA-2026-00640</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4858">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22880 – Mattermost Mobile Apps versions &lt;=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22880</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22880</guid>
    <pubDate>Thu, 21 May 2026 09:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22880</strong></p>
  <p>Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credentials for a legitimate Mattermost server via relaying the SSO code exchange flow through the mobile application. Mattermost Advisory ID: MMSA-2025-00564</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22880">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4055 – Mattermost versions 11.5.x &lt;= 11.5.1 fail to validate team-level run_create perm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4055</guid>
    <pubDate>Thu, 21 May 2026 08:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4055</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1 fail to validate team-level run_create permission against the target team when creating a playbook run which allows an authenticated team member to create runs in teams where they lack permission via specifying a different team ID in the run creation API request. Mattermost Advisory ID: MMSA-2026-00629</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6347 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13, 11.4.x &lt;= 11.4.3 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6347</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6347</guid>
    <pubDate>Mon, 18 May 2026 09:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6347</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a support packet to obtain TURN server credentials via the plaintext values present in the exported plugin configuration.. Mattermost Advisory ID: MMSA-2026-00605</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6347">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6346 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13, 11.4.x &lt;= 11.4.3 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6346</guid>
    <pubDate>Mon, 18 May 2026 09:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6346</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in support packet generation, which allows a Mattermost System Admin or any party with access to a support packet to obtain sensitive credentials in plaintext via downloading a support packet from the System Console.. Mattermost Advisory ID: MMSA-2026-0…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6345 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13, 11.4.x &lt;= 11.4.3 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6345</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6345</guid>
    <pubDate>Mon, 18 May 2026 09:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6345</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user password which allows a malicious attacker to impersonate a user via the use of some of those passwords.. Mattermost Advisory ID: MMSA-2026-00614</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6345">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6343 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13, 11.4.x &lt;= 11.4.3 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6343</guid>
    <pubDate>Mon, 18 May 2026 09:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6343</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/private permissions which allows members without these permissions to access public playbooks via /get.. Mattermost Advisory ID: MMSA-2026-00591</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6339 – Mattermost versions 11.5.x &lt;= 11.5.1, 11.4.x &lt;= 11.4.3 fail to validate the X-Re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6339</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6339</guid>
    <pubDate>Mon, 18 May 2026 09:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6339</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read reveal endpoint which allows an authenticated channel member to force the reveal of a burn-on-read message without recipient consent via a crafted Markdown image tag.. Mattermost Advisory ID: MMSA-2026-00636</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6339">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-6333 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13 fail to validate the H...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6333</guid>
    <pubDate>Mon, 18 May 2026 09:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-6333</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-controlled server via a spoofed Host header.. Mattermost Advisory ID: MMSA-2026-00582</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5163 – Mattermost versions 11.5.x &lt;= 11.5.1 fail to verify channel membership when proc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5163</guid>
    <pubDate>Mon, 18 May 2026 09:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5163</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites which allows an authenticated attacker to read the content of threads in private channels and direct messages they do not have access to via a crafted request to the post rewrite endpoint.. Mattermost Advisory ID: MMSA-2026-00645</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-4643 – Mattermost Desktop App versions &lt;=6.1 6.0.1 5.4.13.0 fail to prevent server-rend...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4643</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4643</guid>
    <pubDate>Mon, 18 May 2026 09:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-4643</strong></p>
  <p>Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server or plugin to crash the desktop client via invoking {{window.close()}} in the renderer context, leading to a denial of service condition at the client level. Mattermost Advisory ID: MMSA-2026-00633</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4643">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-4286 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13 fail to check if {{tea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4286</guid>
    <pubDate>Mon, 18 May 2026 09:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-4286</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating playbooks, allowing users with only {{Manage Playbook Configurations}} permission to change a playbook's team, bypassing manage members restriction via PUT api. Mattermost Advisory ID: MMSA-2025-00552</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3471 – Mattermost Desktop App versions &lt;=6.1 6.0.1 5.4.13.0 fail to prevent an invalid ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3471</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3471</guid>
    <pubDate>Mon, 18 May 2026 09:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3471</strong></p>
  <p>Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated crash the application via calling {{window.open('javascript:alert()');}}. Mattermost Advisory ID: MMSA-2026-00618</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-939</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3471">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3117 – Mattermost Plugins versions &lt;=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly che...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3117</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3117</guid>
    <pubDate>Mon, 18 May 2026 09:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3117</strong></p>
  <p>Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin which allows normal users to uninstall instances or setup webhook connections via the {{gitlab instance {option}}} or the {{/gitlab webhook {option}}} commands. Mattermost Advisory ID: MMSA-2026-00600</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3117">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28732 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13, 11.4.x &lt;= 11.4.3 Fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28732</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28732</guid>
    <pubDate>Mon, 18 May 2026 09:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28732</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom slash commands via editing their own slash command trigger to an already-registered trigger through the comman…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28732">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6342 – Mattermost Plugins versions &lt;=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriatel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6342</guid>
    <pubDate>Mon, 18 May 2026 08:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6342</strong></p>
  <p>Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriately check for valid namespaces which allows plugin users to create subscriptions to groups that were not whitelisted via creating groups that share the same prefix as a whitelisted group. Mattermost Advisory ID: MMSA-2026-00601</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6341 – Mattermost Plugins versions &lt;=11.5 11.1.5 10.13.11 11.3.4.0 fail to have API-lev...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6341</guid>
    <pubDate>Mon, 18 May 2026 08:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6341</strong></p>
  <p>Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to have API-level checks on which groups the user can create issues or attach comments to which allows a user that is member of multiple groups to create issues to a locked group via direct API requests. Mattermost Advisory ID: MMSA-2026-00602</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6340 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13, 11.4.x &lt;= 11.4.3 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6340</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6340</guid>
    <pubDate>Mon, 18 May 2026 08:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6340</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure before processing which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted 7zip file with excessive folder declarations.. Mattermost Advisory ID: MMSA-2026-00573</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6340">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-6334 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13 fail to enforce client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6334</guid>
    <pubDate>Mon, 18 May 2026 08:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-6334</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth authorization code redemption flow which allows an authenticated OAuth client to redeem authorization codes issued to a different client via a crafted token exchange request.. Mattermost Advisory ID: MMSA-2026-00570</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-4273 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13 fail to validate that ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4273</guid>
    <pubDate>Mon, 18 May 2026 08:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-4273</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation which allows an authenticated attacker to bypass token rotation and reuse the original invite token via sending a crafted invite confirmation with a RefreshedToken matching the original token. Mattermost Advisory ID: MM…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3637 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13, 11.4.x &lt;= 11.4.3 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3637</guid>
    <pubDate>Mon, 18 May 2026 08:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3637</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an authenticated attacker with revoked posting privileges to modify their existing posts via direct API requests to the post update and patch endpoints.. Mattermost Advisory ID: MMSA-2026-00627</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-3495 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13 fail to escape some va...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3495</guid>
    <pubDate>Mon, 18 May 2026 08:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-3495</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some malicious code via injecting some JS as part of those values.. Mattermost Advisory ID: MMSA-2026-00622</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2325 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13, 11.4.x &lt;= 11.4.3 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2325</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2325</guid>
    <pubDate>Mon, 18 May 2026 08:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2325</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API endpoint, which allows an authenticated attacker to cause resource exhaustion or denial of service via a crafted oversized HTTP POST request to {{/api/v1/meetings}}.. Mattermost Advisory ID: MMSA-2026-00608</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2325">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28759 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13, 11.4.x &lt;= 11.4.3 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28759</guid>
    <pubDate>Mon, 18 May 2026 08:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28759</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious remote cluster to remove any user from any channel, including private channels, via crafted membership sync messages targeting channels the remote clu…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4054 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13, 11.4.x &lt;= 11.4.3 Fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4054</guid>
    <pubDate>Fri, 15 May 2026 19:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4054</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxied images, which allows a remote attacker to enact client-side DoS via an SVG file served from an attacker-controlled origin under a non-SVG Content-Type header (e.g. image/png) embedded in an og:image meta tag or Markdown image link.. Mattermost Advisory ID: MMSA-2026-00630</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-4053 – Mattermost versions 11.5.x &lt;= 11.5.1, 10.11.x &lt;= 10.11.13 fail to enforce the Po...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4053</guid>
    <pubDate>Fri, 15 May 2026 19:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-4053</strong></p>
  <p>Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has expired via the post patch and update API endpoints.. Mattermost Advisory ID: MMSA-2026-00631</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-672</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45003 – OpenClaw before 2026.4.22 allows workspace dotenv files to override connector en...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45003</guid>
    <pubDate>Mon, 11 May 2026 18:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45003</strong></p>
  <p>OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime traffic to malicious endpoints by setting endpoint variables in dotenv files.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-441</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45003">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3590 – Mattermost versions 10.11.x &lt;= 10.11.12, 11.5.x &lt;= 11.5.0, 11.4.x &lt;= 11.4.2, 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3590</guid>
    <pubDate>Wed, 15 Apr 2026 12:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3590</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid magic link to establish multiple independent authenticated sessions via concurrent requests.. Mattermost Advisory ID: MMSA-2026-00624</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28741 – Mattermost versions 10.11.x &lt;= 10.11.12, 11.5.x &lt;= 11.5.0, 11.4.x &lt;= 11.4.2, 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28741</guid>
    <pubDate>Wed, 15 Apr 2026 11:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28741</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpoint which allows an attacker to update a user's authentication method via a CSRF attack by tricking a user into visiting a malicious page. Mattermost Advisory ID: MMSA-2026-00625</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-27769 – Mattermost versions 10.11.x &lt;= 10.11.12 fail to validate whether users were corr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27769</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27769</guid>
    <pubDate>Wed, 15 Apr 2026 11:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-27769</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed status of local users via the Connected Workspaces API.. Mattermost Advisory ID: MMSA-2026-00603</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27769">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-24661 – Mattermost Plugins versions &lt;=2.1.3.0 fail to limit the request body size on the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24661</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24661</guid>
    <pubDate>Thu, 09 Apr 2026 11:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-24661</strong></p>
  <p>Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24661">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-21388 – Mattermost Plugins versions &lt;=2.3.1 fail to limit the request body size on the {...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21388</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21388</guid>
    <pubDate>Thu, 09 Apr 2026 11:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-21388</strong></p>
  <p>Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21388">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3524 – Mattermost Plugin Legal Hold versions &lt;=1.1.4 fail to halt request processing af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3524</guid>
    <pubDate>Mon, 06 Apr 2026 13:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3524</strong></p>
  <p>Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API requests to the plugin's endpoints. Mattermost Advisory ID: MMSA-2026-00621</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3116 – Mattermost Plugins versions &lt;=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to valid...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3116</guid>
    <pubDate>Thu, 26 Mar 2026 17:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3116</strong></p>
  <p>Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request size which allows an authenticated attacker to cause service disruption via the webhook endpoint. Mattermost Advisory ID: MMSA-2026-00589</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3115 – Mattermost versions 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10, 11.4.x &lt;= 11.4.0, 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3115</guid>
    <pubDate>Thu, 26 Mar 2026 17:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3115</strong></p>
  <p>Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restrictions when retrieving group member IDs, which allows authenticated guest users to enumerate user IDs outside their allowed visibility scope via the group retrieval endpoint.. Mattermost Advisory ID: MMSA-2026-00594</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3114 – Mattermost versions 11.4.x &lt;= 11.4.0, 11.3.x &lt;= 11.3.1, 11.2.x &lt;= 11.2.3, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3114</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3114</guid>
    <pubDate>Thu, 26 Mar 2026 17:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3114</strong></p>
  <p>Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompressed archive entry sizes during file extraction which allows authenticated users with file upload permissions to cause a denial of service via crafted zip archives containing highly compressed entries (zip bombs) that exhaust server memory.. Mattermost Advisory ID: MMSA-2026-00598</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-409</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3114">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3113 – Mattermost versions 11.4.x &lt;= 11.4.0, 11.3.x &lt;= 11.3.1, 11.2.x &lt;= 11.2.3, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3113</guid>
    <pubDate>Thu, 26 Mar 2026 17:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3113</strong></p>
  <p>Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on downloaded bulk export which allows other local users on the server to be able to read contents of the bulk export.. Mattermost Advisory ID: MMSA-2026-00593</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-3112 – Mattermost versions 11.4.x &lt;= 11.4.0, 11.3.x &lt;= 11.3.1, 11.2.x &lt;= 11.2.3, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3112</guid>
    <pubDate>Thu, 26 Mar 2026 17:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-3112</strong></p>
  <p>Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate Advanced Logging file target paths which allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in support packet generation. Mattermost Advisory ID: MMSA-2025-00562</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-3109 – Mattermost Plugins versions &lt;=11.4 10.11.11.0 fail to validate webhook request t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3109</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3109</guid>
    <pubDate>Thu, 26 Mar 2026 17:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-3109</strong></p>
  <p>Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to corrupt Zoom meeting state in Mattermost via replayed webhook requests. Mattermost Advisory ID: MMSA-2026-00584</p>
  <p><strong>CVSS:</strong> 2.2 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3109">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3108 – Mattermost versions 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10, 11.4.x &lt;= 11.4.0, 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3108</guid>
    <pubDate>Thu, 26 Mar 2026 17:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3108</strong></p>
  <p>Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-controlled post content in the mmctl commands terminal output which allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences that enable screen manipulation, fake prompts, and clipboard hijacking.. Mattermost Advisory ID: M…</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-150</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4274 – Mattermost versions 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10, 11.4.x &lt;= 11.4.0, 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4274</guid>
    <pubDate>Thu, 26 Mar 2026 11:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4274</strong></p>
  <p>Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-level access when processing membership sync from a remote cluster, which allows a malicious remote cluster to grant a user access to an entire private team instead of only the shared channel via sending crafted membership sync messages that trigger team membership assignment. Matte…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27659 – Mattermost versions 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10, 11.4.x &lt;= 11.4.0, 11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27659</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27659</strong></p>
  <p>Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to properly validate CSRF tokens in the /api/v4/access_control_policies/{policy_id}/activate endpoint, which allows an attacker to trick an admin into changing access control policy active status via a crafted request.. Mattermost Advisory ID: MMSA-2026-00578</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27656 – Mattermost versions 11.4.x &lt;= 11.4.0, 11.3.x &lt;= 11.3.1, 11.2.x &lt;= 11.2.3, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27656</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27656</strong></p>
  <p>Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to properly validate user identity in the OpenID {{IsSameUser()}} comparison logic, which allows an attacker to take over arbitrary user accounts via an overly permissive substring matching flaw in the user discovery flow.. Mattermost Advisory ID: MMSA-2026-00590</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-303</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-26233 – Mattermost versions 11.4.x &lt;= 11.4.0, 11.3.x &lt;= 11.3.1, 11.2.x &lt;= 11.2.3, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26233</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-26233</strong></p>
  <p>Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to rate limit login requests which allows unauthenticated remote attackers to cause denial of service (server crash and restart) via HTTP/2 single packet attack with 100+ parallel login requests.. Mattermost Advisory ID: MMSA-2025-00566</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-20719 – Mattermost versions 11.4.x &lt;= 11.4.0, 11.3.x &lt;= 11.3.1, 11.2.x &lt;= 11.2.3, 10.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20719</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20719</guid>
    <pubDate>Wed, 25 Mar 2026 17:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-20719</strong></p>
  <p>Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering of external SVGs on link embeds which allows unauthenticated users to crash the Mattermost webapp and desktop app via creating an issue or PR on GitHub.. Mattermost Advisory ID: MMSA-2026-00595</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20719">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2454 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2454</guid>
    <pubDate>Mon, 16 Mar 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2454</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to cause OOM errors and crash the server via sending corrupted msgpack frames within websocket messages to calls plugin. Mattermost Advisory ID: MMSA-2025-00537</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-26230 – Mattermost versions 10.11.x &lt;= 10.11.10 fail to properly validate permission req...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26230</guid>
    <pubDate>Mon, 16 Mar 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-26230</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.10 fail to properly validate permission requirements in the team member roles API endpoint which allows team administrators to demote members to guest role. Mattermost Advisory ID: MMSA-2025-00531</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1629 – Mattermost versions 10.11.x &lt;= 10.11.10 Fail to invalidate cached permalink prev...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1629</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1629</guid>
    <pubDate>Mon, 16 Mar 2026 21:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1629</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel access which allows the user to continue viewing private channel content via previously cached permalink previews until cache reset or relogin.. Mattermost Advisory ID: MMSA-2026-00580</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-672</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1629">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-26304 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2 fail to verify run_create...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26304</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26304</guid>
    <pubDate>Mon, 16 Mar 2026 20:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-26304</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2 fail to verify run_create permission for empty playbookId, which allows team members to create unauthorized runs via the playbook run API. Mattermost Advisory ID: MMSA-2025-00542</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26304">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2455 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2455</guid>
    <pubDate>Mon, 16 Mar 2026 15:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2455</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation which allows an attacker to perform SSRF attacks against internal services via IPv4-mapped IPv6 literals (e.g., [::ffff:127.0.0.1]).. Mattermost Advisory ID: MMSA-2026-00585</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24692 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24692</guid>
    <pubDate>Mon, 16 Mar 2026 15:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24692</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in search API endpoints which allows guest users without read permissions to access posts and files in channels via search API requests. Mattermost Advisory ID: MMSA-2025-00554</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-22545 – Mattermost versions 10.11.x &lt;= 10.11.10 fail to validate user's authentication m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22545</guid>
    <pubDate>Mon, 16 Mar 2026 15:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-22545</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.10 fail to validate user's authentication method when processing account auth type switch which allows an authenticated attacker to change account password without confirmation via falsely claiming a different auth provider.. Mattermost Advisory ID: MMSA-2026-00583</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21386 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21386</guid>
    <pubDate>Mon, 16 Mar 2026 15:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21386</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know about via differing error messages for nonexistent versus private channels. Mattermost Advisory ID: MMSA-2026-00588</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4265 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4265</guid>
    <pubDate>Mon, 16 Mar 2026 14:20:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4265</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in channels where they lack upload_file permission via uploading files in a team where they have permission and reusing the file metadata in a POST request to a different team. Mattermost Advisory ID: MMSA-2025-00553</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2578 – Mattermost versions 11.3.x &lt;= 11.3.0 fail to preserve the redacted state of burn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2578</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2578</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event.. Mattermost Advisory ID: MMSA-2026-00579</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2476 – Mattermost Plugins versions &lt;=2.0.3.0 fail to properly mask sensitive configurat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2476</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2476</strong></p>
  <p>Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2463 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2463</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2463</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2463</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs during team creation.. Mattermost Advisory ID: MMSA-2025-00565</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2463">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2462 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2462</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2462</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2462</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltrate sensitive configuration data including AWS and SMTP credentials via uploading a malicious plugin after changing the import directory. Mattermost…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2462">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2461 – Mattermost Plugins versions &lt;=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement au...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2461</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2461</strong></p>
  <p>Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modifications, which allows an authorised attacker with editor permission to modify comments created by other board members.  Mattermost Advisory ID: MMSA-2025-00559</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2458 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2458</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2458</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership when searching channels which allows a removed team member to enumerate all public channels within a private team via the channel search API endpoint.. Mattermost Advisory ID: MMSA-2025-00568</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2457 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2457</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2457</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonating other users via crafted PUT requests to the post update API endpoint.. Mattermost Advisory ID: MMSA-2025-00569</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2456 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 Matt...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2456</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2456</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of responses from integration action endpoints, which allows an authenticated attacker to cause server memory exhaustion and denial of service via a malicious integration server that returns an arbitrarily large response when a user clicks an interactive message button.. Mattermost Advis…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-26246 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26246</guid>
    <pubDate>Mon, 16 Mar 2026 14:18:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-26246</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing PSD image files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted PSD file. Mattermost Advisory ID: MMSA-2026-00572</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25783 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25783</guid>
    <pubDate>Mon, 16 Mar 2026 14:18:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25783</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a specially crafted User-Agent header. Mattermost Advisory ID: MMSA-2026-00586</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25780 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25780</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25780</guid>
    <pubDate>Mon, 16 Mar 2026 14:18:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25780</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing DOC files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted DOC file.. Mattermost Advisory ID: MMSA-2026-00581</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25780">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24458 – Mattermost versions 11.3.x &lt;= 11.3.0, 11.2.x &lt;= 11.2.2, 10.11.x &lt;= 10.11.10 fail...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24458</guid>
    <pubDate>Mon, 16 Mar 2026 14:18:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24458</strong></p>
  <p>Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and memory via executing login attempts with multi-megabyte passwords. Mattermost Advisory ID: MMSA-2026-00587</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-1628 – Mattermost Desktop App versions &lt;=5.13.3 fail to attach listeners restricting na...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1628</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1628</guid>
    <pubDate>Mon, 02 Mar 2026 14:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-1628</strong></p>
  <p>Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an external link in their Mattermost server. Mattermost Advisory ID: MMSA-2026-00596</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1628">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1046 – Mattermost Desktop App versions &lt;=6.0 6.2.0 5.2.13.0 fail to validate help links...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1046</guid>
    <pubDate>Mon, 16 Feb 2026 13:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1046</strong></p>
  <p>Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisory ID: MMSA-2026-00577</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-939</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-14573 – Mattermost versions 10.11.x &lt;= 10.11.9 fail to enforce invite permissions when u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14573</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14573</guid>
    <pubDate>Mon, 16 Feb 2026 13:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-14573</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisory ID: MMSA-2025-00561</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14573">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14350 – Mattermost versions 11.1.x &lt;= 11.1.2, 10.11.x &lt;= 10.11.9, 11.2.x &lt;= 11.2.1 fail ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14350</guid>
    <pubDate>Mon, 16 Feb 2026 13:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14350</strong></p>
  <p>Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated users to determine the existence of teams and their URL names via posting channel shortlinks and observing the channel_mentions property in the API response. Mattermost Advisory ID: MMSA-2025-00563</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13821 – Mattermost versions 11.1.x &lt;= 11.1.2, 10.11.x &lt;= 10.11.9, 11.2.x &lt;= 11.2.1 fail ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13821</guid>
    <pubDate>Mon, 16 Feb 2026 12:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13821</strong></p>
  <p>Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate password hashes and MFA secrets via profile nickname updates or email verification events. Mattermost Advisory ID: MMSA-2025-00560</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0999 – Mattermost versions 11.1.x &lt;= 11.1.2, 10.11.x &lt;= 10.11.9, 11.2.x &lt;= 11.2.1 fail ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0999</guid>
    <pubDate>Mon, 16 Feb 2026 10:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0999</strong></p>
  <p>Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-only login requirements via userID-based authentication. Mattermost Advisory ID: MMSA-2025-00548</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-303</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0999">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0998 – Mattermost versions 11.1.x &lt;= 11.1.2, 10.11.x &lt;= 10.11.9, 11.2.x &lt;= 11.2.1 and M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0998</guid>
    <pubDate>Mon, 16 Feb 2026 10:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0998</strong></p>
  <p>Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post ownership in the {{/api/v1/askPMI}} endpoint which allows unauthorized users to start Zoom meetings as any user and overwrite arbitrary posts via direct API calls with manipulated user IDs and post data.. Mattermost Advisory ID: MMSA-2025-…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-0997 – Mattermost versions 11.1.x &lt;= 11.1.2, 10.11.x &lt;= 10.11.9, 11.2.x &lt;= 11.2.1 and M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0997</guid>
    <pubDate>Mon, 16 Feb 2026 10:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-0997</strong></p>
  <p>Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/channel-preference}}, which allows any logged-in user to change Zoom meeting restrictions for arbitrary channels via crafted API requests.. Mattermost Advisory ID: MMSA-2025-00558</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22892 – Mattermost versions 11.1.x &lt;= 11.1.2, 10.11.x &lt;= 10.11.9, 11.2.x &lt;= 11.2.1 fail ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22892</guid>
    <pubDate>Fri, 13 Feb 2026 11:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22892</strong></p>
  <p>Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to validate user permissions when creating Jira issues from Mattermost posts, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to via the /create-issue API endpoint by providing the post ID of an inaccessible post.. Matterm…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-20796 – Mattermost versions 10.11.x &lt;= 10.11.9 fail to properly validate channel members...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20796</guid>
    <pubDate>Fri, 13 Feb 2026 11:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-20796</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to via a race condition in the /common_teams API endpoint.. Mattermost Advisory ID: MMSA-2025-00549</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13523 – Mattermost Confluence plugin version &lt;1.7.0 fails to properly escape user-contro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13523</guid>
    <pubDate>Fri, 06 Feb 2026 16:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13523</strong></p>
  <p>Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially crafted OAuth2 connection link that, when visited, renders the attacker's display name without proper sanitization. Mattermos…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-14435 – Mattermost versions 10.11.x &lt;= 10.11.8, 11.1.x &lt;= 11.1.1, 11.0.x &lt;= 11.0.6 fail ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14435</guid>
    <pubDate>Fri, 16 Jan 2026 12:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-14435</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticated users to cause application-level DoS via triggering unbounded component re-render loops.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-14822 – Mattermost versions 10.11.x &lt;= 10.11.8 fail to validate input size before proces...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14822</guid>
    <pubDate>Fri, 16 Jan 2026 09:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-14822</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-407</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64641 – Mattermost versions 11.1.x &lt;= 11.1.0, 11.0.x &lt;= 11.0.5, 10.12.x &lt;= 10.12.3, 10.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64641</guid>
    <pubDate>Wed, 24 Dec 2025 08:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64641</strong></p>
  <p>Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jira tickets when victim users interacted with affected posts</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-13767 – Mattermost versions 11.1.x &lt;= 11.1.0, 11.0.x &lt;= 11.0.5, 10.12.x &lt;= 10.12.3, 10.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13767</guid>
    <pubDate>Wed, 24 Dec 2025 08:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-13767</strong></p>
  <p>Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14273 – Mattermost versions 11.1.x &lt;= 11.1.0, 11.0.x &lt;= 11.0.5, 10.12.x &lt;= 10.12.3, 10.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14273</guid>
    <pubDate>Mon, 22 Dec 2025 12:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14273</strong></p>
  <p>Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the Jira plugin, which allows an unauthenticated attacker who knows a valid user ID to issue authenticated GET and POST requests to the Jira server via crafted plugi…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-303</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-13326 – Mattermost Desktop App versions &lt;6.0.0 fail to enable the Hardened Runtime on th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13326</guid>
    <pubDate>Wed, 17 Dec 2025 19:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-13326</strong></p>
  <p>Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.</p>
  <p><strong>CVSS:</strong> 3.9 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-13324 – Mattermost versions 10.11.x &lt;= 10.11.5, 11.0.x &lt;= 11.0.4, 10.12.x &lt;= 10.12.2 fai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13324</guid>
    <pubDate>Wed, 17 Dec 2025 19:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-13324</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an invite token to authenticate as the remote cluster and perform limited actions on shared channels even after the invitati…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-13321 – Mattermost Desktop App versions &lt;6.0.0 fail to sanitize sensitive information fr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13321</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13321</guid>
    <pubDate>Wed, 17 Dec 2025 19:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-13321</strong></p>
  <p>Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13321">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-12689 – Mattermost versions 11.0.x &lt;= 11.0.4, 10.12.x &lt;= 10.12.2, 10.11.x &lt;= 10.11.6 fai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12689</guid>
    <pubDate>Wed, 17 Dec 2025 19:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-12689</strong></p>
  <p>Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to crash Calls plug-in via sending malformed request.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-62690 – Mattermost versions 10.11.x &lt;= 10.11.4 fail to validate redirect URLs on the /er...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62690</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62690</guid>
    <pubDate>Wed, 17 Dec 2025 13:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-62690</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link opened in a new tab.</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62690">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62190 – Mattermost versions 11.0.x &lt;= 11.0.4, 10.12.x &lt;= 10.12.2, 10.11.x &lt;= 10.11.6 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62190</guid>
    <pubDate>Wed, 17 Dec 2025 13:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62190</strong></p>
  <p>Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inject messages into channels or direct messages via a malicious webpage or crafted link</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62190">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-13352 – Mattermost versions 10.11.x &lt;= 10.11.6 and Mattermost GitHub plugin versions &lt;=2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13352</guid>
    <pubDate>Wed, 17 Dec 2025 13:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-13352</strong></p>
  <p>Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.</p>
  <p><strong>CVSS:</strong> 3.0 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13352">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
