CVE-2026-16045
- EPSS 0.2%
- Veröffentlicht 17.08.2026 14:26:22
- Zuletzt bearbeitet 18.08.2026 20:32:18
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 Mattermost failed to restrict OAuth deauthorization and personal access token management endpoints to direct user sessions, which allowed an OAuth app with a delegated user token to revoke the...
CVE-2026-16049
- EPSS 0.22%
- Veröffentlicht 17.08.2026 14:25:45
- Zuletzt bearbeitet 18.08.2026 15:04:46
Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails to validate the_ {{web_url}} _parameter against the co...
CVE-2026-16047
- EPSS 0.16%
- Veröffentlicht 17.08.2026 14:25:08
- Zuletzt bearbeitet 18.08.2026 20:41:36
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate that users have read access to a channel before linking a board to it, which allows an authenticated attacker to discover the membership of private channels ...
CVE-2026-16046
- EPSS 0.15%
- Veröffentlicht 17.08.2026 14:24:14
- Zuletzt bearbeitet 18.08.2026 20:34:52
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to enforce run-state validation on write operations for finished playbook runs which allows a run participant to modify status, checklists, retrospective content, ownership, and participa...
CVE-2026-16048
- EPSS 0.15%
- Veröffentlicht 17.08.2026 14:22:43
- Zuletzt bearbeitet 18.08.2026 20:42:05
Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additional channel permissions via the channel member rol...
CVE-2026-14298
- EPSS 0.24%
- Veröffentlicht 13.08.2026 08:03:00
- Zuletzt bearbeitet 14.09.2026 11:17:03
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler, which allows an authenticated use...
CVE-2026-7521
- EPSS 0.28%
- Veröffentlicht 28.07.2026 13:58:31
- Zuletzt bearbeitet 29.07.2026 15:06:39
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin with SAML system-console write permissions to delete arbitrary files outside the config directory fr...
CVE-2026-10819
- EPSS 0.24%
- Veröffentlicht 27.07.2026 14:15:25
- Zuletzt bearbeitet 03.08.2026 15:23:50
Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of servic...
CVE-2026-10600
- EPSS 0.22%
- Veröffentlicht 27.07.2026 14:13:29
- Zuletzt bearbeitet 03.08.2026 15:24:46
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to...
CVE-2026-8075
- EPSS 0.24%
- Veröffentlicht 17.07.2026 10:05:06
- Zuletzt bearbeitet 30.07.2026 14:44:35
Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a malicious link with an embedded ...