CVE-2026-11993
- EPSS 0.21%
- Veröffentlicht 14.09.2026 10:29:19
- Zuletzt bearbeitet 07.10.2026 16:23:58
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload files to spaw...
CVE-2026-14259
- EPSS 0.15%
- Veröffentlicht 14.09.2026 10:26:41
- Zuletzt bearbeitet 07.10.2026 16:08:13
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or Private boards...
CVE-2026-75587
- EPSS 0.1%
- Veröffentlicht 17.08.2026 22:09:49
- Zuletzt bearbeitet 19.08.2026 15:53:15
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret confi...
CVE-2026-9693
- EPSS 0.16%
- Veröffentlicht 17.08.2026 22:07:12
- Zuletzt bearbeitet 19.08.2026 13:14:34
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private ch...
CVE-2026-9859
- EPSS 0.25%
- Veröffentlicht 17.08.2026 22:06:26
- Zuletzt bearbeitet 19.08.2026 13:28:57
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which allows an authenticated board editor to relink any board they can edit to an ar...
CVE-2026-9816
- EPSS 0.25%
- Veröffentlicht 17.08.2026 22:05:24
- Zuletzt bearbeitet 19.08.2026 13:29:28
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMember.Scheme* fields server-side on insert and archive-import paths which allows a board editor or non-guest team member to grant board admin to arbitr...
CVE-2026-10080
- EPSS 0.29%
- Veröffentlicht 17.08.2026 22:04:30
- Zuletzt bearbeitet 18.08.2026 16:19:17
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authenticated user to crash the plugin process and deny service to all Boards users via a custom_focalboard_SU...
CVE-2026-10527
- EPSS 0.15%
- Veröffentlicht 17.08.2026 14:37:46
- Zuletzt bearbeitet 18.08.2026 20:21:57
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to reconcile SchemeAdmin flags with a user's current role which allows a user demoted to System Guest to retain Board Admin privileges and perform admin-only operations...
CVE-2026-15754
- EPSS 0.15%
- Veröffentlicht 17.08.2026 14:36:56
- Zuletzt bearbeitet 18.08.2026 20:24:58
Mattermost versions 11.7.x <= 11.7.6, 11.8.x <= 11.8.3 The access control policy unassign endpoint fails to re-validate that each target channel still belongs to the requesting admin's team, which allows an authenticated team administrator to remove ...
CVE-2026-16044
- EPSS 0.17%
- Veröffentlicht 17.08.2026 14:26:52
- Zuletzt bearbeitet 18.08.2026 20:27:55
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privileges during board archive import which allows a board member to escalate a guest user to Board Admin via importing a crafted .board...