CVE-2026-2455
- EPSS 0.03%
- Veröffentlicht 16.03.2026 14:53:31
- Zuletzt bearbeitet 18.03.2026 13:55:00
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation which allows an attacker to perform SSRF attacks against internal services via IPv4-mapped IPv6 ...
CVE-2026-21386
- EPSS 0.04%
- Veröffentlicht 16.03.2026 14:51:43
- Zuletzt bearbeitet 18.03.2026 13:53:15
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to use consistent error responses when handling the /mute command which allows an authenticated team member to enumerate private channels they are not authorized to know...
CVE-2026-25780
- EPSS 0.05%
- Veröffentlicht 16.03.2026 12:59:13
- Zuletzt bearbeitet 18.03.2026 18:13:33
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing DOC files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a speci...
CVE-2026-4265
- EPSS 0.03%
- Veröffentlicht 16.03.2026 12:07:14
- Zuletzt bearbeitet 18.03.2026 17:41:56
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in channels where they lack upload_file permission via uploading files in a tea...
CVE-2026-25783
- EPSS 0.08%
- Veröffentlicht 16.03.2026 12:04:18
- Zuletzt bearbeitet 18.03.2026 18:11:16
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a specially crafted User-Agent header. Mattermost Advis...
CVE-2026-24458
- EPSS 0.06%
- Veröffentlicht 16.03.2026 12:02:23
- Zuletzt bearbeitet 18.03.2026 18:14:11
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and memory via executing login attempts with multi-megabyte passwords. Matter...
CVE-2026-2462
- EPSS 0.2%
- Veröffentlicht 16.03.2026 12:00:21
- Zuletzt bearbeitet 18.03.2026 18:31:45
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to restrict plugin installation on CI test instances with default admin credentials which allows an unauthenticated attacker to achieve remote code execution and exfiltr...
CVE-2026-2578
- EPSS 0.04%
- Veröffentlicht 16.03.2026 11:58:09
- Zuletzt bearbeitet 18.03.2026 17:42:38
Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event.. Mattermost Advisory...
CVE-2026-26246
- EPSS 0.05%
- Veröffentlicht 16.03.2026 11:33:02
- Zuletzt bearbeitet 18.03.2026 18:03:54
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing PSD image files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a...
CVE-2026-2458
- EPSS 0.03%
- Veröffentlicht 16.03.2026 11:27:49
- Zuletzt bearbeitet 18.03.2026 17:48:32
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership when searching channels which allows a removed team member to enumerate all public channels within a private team via the channel se...