CVE-2026-8821
- EPSS 0.17%
- Veröffentlicht 14.09.2026 10:42:42
- Zuletzt bearbeitet 07.10.2026 15:43:05
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrary user to a r...
CVE-2026-5132
- EPSS 0.24%
- Veröffentlicht 14.09.2026 10:41:42
- Zuletzt bearbeitet 07.10.2026 15:43:56
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service or crash server via sending many SDP messages that u...
CVE-2026-15814
- EPSS 0.24%
- Veröffentlicht 14.09.2026 10:39:45
- Zuletzt bearbeitet 07.10.2026 16:02:31
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause excessive server memory consumpt...
CVE-2026-10542
- EPSS 0.13%
- Veröffentlicht 14.09.2026 10:37:32
- Zuletzt bearbeitet 07.10.2026 16:32:30
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel action ownership which allows channel managers to update actions in other channels via the channel action update endpoint.. Matterm...
CVE-2026-14344
- EPSS 0.15%
- Veröffentlicht 14.09.2026 10:33:54
- Zuletzt bearbeitet 07.10.2026 16:07:36
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-and-blocks, a...
CVE-2026-12882
- EPSS 0.21%
- Veröffentlicht 14.09.2026 10:30:39
- Zuletzt bearbeitet 07.10.2026 16:23:29
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Markdown autolinks with unmatched trailing closing parentheses in linear time, which allows an authenticated user with permission to create po...
CVE-2026-11993
- EPSS 0.21%
- Veröffentlicht 14.09.2026 10:29:19
- Zuletzt bearbeitet 07.10.2026 16:23:58
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload files to spaw...
CVE-2026-14259
- EPSS 0.15%
- Veröffentlicht 14.09.2026 10:26:41
- Zuletzt bearbeitet 07.10.2026 16:08:13
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or Private boards...
CVE-2026-9693
- EPSS 0.16%
- Veröffentlicht 17.08.2026 22:07:12
- Zuletzt bearbeitet 19.08.2026 13:14:34
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private ch...
CVE-2026-9859
- EPSS 0.25%
- Veröffentlicht 17.08.2026 22:06:26
- Zuletzt bearbeitet 19.08.2026 13:28:57
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink any board they can edit to an ar...