CVE-2026-96260
- EPSS 0.41%
- Veröffentlicht 22.09.2026 20:34:49
- Zuletzt bearbeitet 07.10.2026 16:37:42
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust server memory and cause a ...
CVE-2026-96259
- EPSS 0.26%
- Veröffentlicht 22.09.2026 20:34:20
- Zuletzt bearbeitet 07.10.2026 16:41:14
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which allows a System Administrator to make the server issue requests to internal n...
CVE-2026-95666
- EPSS 0.36%
- Veröffentlicht 22.09.2026 13:11:13
- Zuletzt bearbeitet 07.10.2026 16:48:51
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted by the bulk reactions endpoint which allows an authenticated user to cause excessive database load vi...
CVE-2026-12284
- EPSS 0.13%
- Veröffentlicht 17.09.2026 15:11:52
- Zuletzt bearbeitet 18.09.2026 13:46:33
Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an active call b...
CVE-2026-75588
- EPSS 0.17%
- Veröffentlicht 17.09.2026 15:09:40
- Zuletzt bearbeitet 18.09.2026 13:46:33
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insecure connectio...
CVE-2026-75025
- EPSS 0.15%
- Veröffentlicht 16.09.2026 18:27:02
- Zuletzt bearbeitet 17.09.2026 19:16:57
Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. Thanks to game0v3r for contributing to this improvement und...
CVE-2026-91181
- EPSS 0.23%
- Veröffentlicht 14.09.2026 21:21:47
- Zuletzt bearbeitet 07.10.2026 16:49:26
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data Retention Pol...
CVE-2026-12985
- EPSS 0.28%
- Veröffentlicht 14.09.2026 14:09:53
- Zuletzt bearbeitet 07.10.2026 17:58:56
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a remote unauth...
CVE-2026-82920
- EPSS 0.15%
- Veröffentlicht 14.09.2026 13:59:01
- Zuletzt bearbeitet 07.10.2026 18:04:00
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC parent policy...
CVE-2026-86348
- EPSS 0.22%
- Veröffentlicht 14.09.2026 13:52:24
- Zuletzt bearbeitet 16.09.2026 19:30:49
Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.. Mattermost Advisory ID: MMSA-2026-00701