CVE-2026-2457
- EPSS 0.02%
- Veröffentlicht 16.03.2026 11:20:25
- Zuletzt bearbeitet 18.03.2026 17:49:10
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonating other users via crafted PUT requests to the post...
CVE-2026-2461
- EPSS 0.04%
- Veröffentlicht 16.03.2026 11:16:32
- Zuletzt bearbeitet 20.03.2026 18:30:35
Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modifications, which allows an authorised attacker with editor permission to modify comments created by other board members. Mattermo...
CVE-2026-2463
- EPSS 0.03%
- Veröffentlicht 16.03.2026 11:13:57
- Zuletzt bearbeitet 18.03.2026 17:43:26
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs...
CVE-2026-2456
- EPSS 0.04%
- Veröffentlicht 16.03.2026 11:06:44
- Zuletzt bearbeitet 18.03.2026 18:27:57
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of responses from integration action endpoints, which allows an authenticated attacker to cause server memory exhaustion and denial of serv...
CVE-2025-14573
- EPSS 0.03%
- Veröffentlicht 16.02.2026 12:25:32
- Zuletzt bearbeitet 18.02.2026 20:18:01
Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisor...
CVE-2025-13821
- EPSS 0.04%
- Veröffentlicht 16.02.2026 12:16:21
- Zuletzt bearbeitet 18.02.2026 21:44:27
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate password hashes and MFA secrets via profile nickname updates or email veri...
CVE-2025-14350
- EPSS 0.04%
- Veröffentlicht 16.02.2026 12:05:33
- Zuletzt bearbeitet 18.02.2026 20:19:20
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated users to determine the existence of teams and their URL names via posting...
CVE-2026-0997
- EPSS 0.04%
- Veröffentlicht 16.02.2026 10:16:07
- Zuletzt bearbeitet 18.02.2026 20:23:34
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/channel-preference}}, which allows any logged-in us...
CVE-2026-0998
- EPSS 0.04%
- Veröffentlicht 16.02.2026 10:16:07
- Zuletzt bearbeitet 18.02.2026 20:22:51
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post ownership in the {{/api/v1/askPMI}} endpoint which allows unauthorized users to start Zoom...
CVE-2026-0999
- EPSS 0.05%
- Veröffentlicht 16.02.2026 09:47:45
- Zuletzt bearbeitet 18.02.2026 20:20:07
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-only login requirements via userID-based authentication. Mattermost Adviso...