CVE-2026-2456
- EPSS 0.04%
- Veröffentlicht 16.03.2026 11:06:44
- Zuletzt bearbeitet 18.03.2026 18:27:57
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of responses from integration action endpoints, which allows an authenticated attacker to cause server memory exhaustion and denial of serv...
CVE-2026-1628
- EPSS 0.03%
- Veröffentlicht 02.03.2026 13:24:21
- Zuletzt bearbeitet 05.03.2026 16:07:40
Mattermost Desktop App versions <=5.13.3 fail to attach listeners restricting navigation to external sites within the Mattermost app which allows a malicious server to expose preload script functionality to untrusted servers via having a user open an...
CVE-2025-14573
- EPSS 0.03%
- Veröffentlicht 16.02.2026 12:25:32
- Zuletzt bearbeitet 18.02.2026 20:18:01
Mattermost versions 10.11.x <= 10.11.9 fail to enforce invite permissions when updating team settings, which allows team administrators without proper permissions to bypass restrictions and add users to their team via API requests. Mattermost Advisor...
CVE-2025-13821
- EPSS 0.04%
- Veröffentlicht 16.02.2026 12:16:21
- Zuletzt bearbeitet 18.02.2026 21:44:27
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate password hashes and MFA secrets via profile nickname updates or email veri...
CVE-2026-1046
- EPSS 0.04%
- Veröffentlicht 16.02.2026 12:10:38
- Zuletzt bearbeitet 23.03.2026 17:27:17
Mattermost Desktop App versions <=6.0 6.2.0 5.2.13.0 fail to validate help links which allows a malicious Mattermost server to execute arbitrary executables on a user’s system via the user clicking on certain items in the Help menu Mattermost Advisor...
CVE-2025-14350
- EPSS 0.03%
- Veröffentlicht 16.02.2026 12:05:33
- Zuletzt bearbeitet 18.02.2026 20:19:20
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate team membership when processing channel mentions which allows authenticated users to determine the existence of teams and their URL names via posting...
CVE-2026-0997
- EPSS 0.04%
- Veröffentlicht 16.02.2026 10:16:07
- Zuletzt bearbeitet 18.02.2026 20:23:34
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate the authenticated user when processing {{/plugins/zoom/api/v1/channel-preference}}, which allows any logged-in us...
CVE-2026-0998
- EPSS 0.04%
- Veröffentlicht 16.02.2026 10:16:07
- Zuletzt bearbeitet 18.02.2026 20:22:51
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 and Mattermost Plugin Zoom versions <=1.11.0 fail to validate user identity and post ownership in the {{/api/v1/askPMI}} endpoint which allows unauthorized users to start Zoom...
CVE-2026-0999
- EPSS 0.05%
- Veröffentlicht 16.02.2026 09:47:45
- Zuletzt bearbeitet 18.02.2026 20:20:07
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-only login requirements via userID-based authentication. Mattermost Adviso...
CVE-2026-20796
- EPSS 0.01%
- Veröffentlicht 13.02.2026 10:30:03
- Zuletzt bearbeitet 23.02.2026 15:53:11
Mattermost versions 10.11.x <= 10.11.9 fail to properly validate channel membership at the time of data retrieval which allows a deactivated user to learn team names they should not have access to via a race condition in the /common_teams API endpoin...