CVE-2026-86349
- EPSS 0.22%
- Veröffentlicht 14.09.2026 13:51:30
- Zuletzt bearbeitet 07.10.2026 17:59:29
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting depth in the server-side Markdown parser which allows an authenticated attacker to cause a denial of service (CPU resource exhaust...
CVE-2026-10556
- EPSS 0.25%
- Veröffentlicht 14.09.2026 10:46:01
- Zuletzt bearbeitet 07.10.2026 16:25:31
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft Calendar plu...
CVE-2026-13417
- EPSS 0.21%
- Veröffentlicht 14.09.2026 10:44:59
- Zuletzt bearbeitet 07.10.2026 16:17:21
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a board to crash the Boards plug...
CVE-2026-9812
- EPSS 0.21%
- Veröffentlicht 14.09.2026 10:43:45
- Zuletzt bearbeitet 06.10.2026 17:55:57
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run property-managemen...
CVE-2026-8821
- EPSS 0.17%
- Veröffentlicht 14.09.2026 10:42:42
- Zuletzt bearbeitet 07.10.2026 15:43:05
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrary user to a r...
CVE-2026-5132
- EPSS 0.24%
- Veröffentlicht 14.09.2026 10:41:42
- Zuletzt bearbeitet 07.10.2026 15:43:56
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service or crash server via sending many SDP messages that u...
CVE-2026-15814
- EPSS 0.24%
- Veröffentlicht 14.09.2026 10:39:45
- Zuletzt bearbeitet 07.10.2026 16:02:31
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause excessive server memory consumpt...
CVE-2026-10542
- EPSS 0.13%
- Veröffentlicht 14.09.2026 10:37:32
- Zuletzt bearbeitet 07.10.2026 16:32:30
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel action ownership which allows channel managers to update actions in other channels via the channel action update endpoint.. Matterm...
CVE-2026-14344
- EPSS 0.15%
- Veröffentlicht 14.09.2026 10:33:54
- Zuletzt bearbeitet 07.10.2026 16:07:36
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-and-blocks, a...
CVE-2026-12882
- EPSS 0.21%
- Veröffentlicht 14.09.2026 10:30:39
- Zuletzt bearbeitet 07.10.2026 16:23:29
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Markdown autolinks with unmatched trailing closing parentheses in linear time, which allows an authenticated user with permission to create po...