CVE-2026-96260
- EPSS 0.41%
- Veröffentlicht 22.09.2026 20:34:49
- Zuletzt bearbeitet 07.10.2026 16:37:42
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust server memory and cause a ...
CVE-2026-96259
- EPSS 0.26%
- Veröffentlicht 22.09.2026 20:34:20
- Zuletzt bearbeitet 07.10.2026 16:41:14
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which allows a System Administrator to make the server issue requests to internal n...
CVE-2026-95666
- EPSS 0.36%
- Veröffentlicht 22.09.2026 13:11:13
- Zuletzt bearbeitet 07.10.2026 16:48:51
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted by the bulk reactions endpoint which allows an authenticated user to cause excessive database load vi...
CVE-2026-91181
- EPSS 0.23%
- Veröffentlicht 14.09.2026 21:21:47
- Zuletzt bearbeitet 07.10.2026 16:49:26
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data Retention Pol...
CVE-2026-12985
- EPSS 0.28%
- Veröffentlicht 14.09.2026 14:09:53
- Zuletzt bearbeitet 07.10.2026 17:58:56
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a remote unauth...
CVE-2026-82920
- EPSS 0.15%
- Veröffentlicht 14.09.2026 13:59:01
- Zuletzt bearbeitet 07.10.2026 18:04:00
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC parent policy...
CVE-2026-86349
- EPSS 0.22%
- Veröffentlicht 14.09.2026 13:51:30
- Zuletzt bearbeitet 07.10.2026 17:59:29
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting depth in the server-side Markdown parser which allows an authenticated attacker to cause a denial of service (CPU resource exhaust...
CVE-2026-10556
- EPSS 0.25%
- Veröffentlicht 14.09.2026 10:46:01
- Zuletzt bearbeitet 07.10.2026 16:25:31
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft Calendar plu...
CVE-2026-13417
- EPSS 0.21%
- Veröffentlicht 14.09.2026 10:44:59
- Zuletzt bearbeitet 07.10.2026 16:17:21
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a board to crash the Boards plug...
CVE-2026-9812
- EPSS 0.21%
- Veröffentlicht 14.09.2026 10:43:45
- Zuletzt bearbeitet 06.10.2026 17:55:57
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run property-managemen...