CVE-2026-9602
- EPSS 0.24%
- Veröffentlicht 17.07.2026 10:03:26
- Zuletzt bearbeitet 30.07.2026 14:38:53
Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing the payload of a method to a mal...
CVE-2026-6541
- EPSS 0.15%
- Veröffentlicht 13.07.2026 10:53:15
- Zuletzt bearbeitet 13.07.2026 20:39:12
Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric setting...
CVE-2026-9820
- EPSS 0.15%
- Veröffentlicht 13.07.2026 10:51:34
- Zuletzt bearbeitet 13.07.2026 20:38:36
Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share acces...
CVE-2026-9824
- EPSS 0.16%
- Veröffentlicht 13.07.2026 10:47:33
- Zuletzt bearbeitet 13.07.2026 20:38:00
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate config...
CVE-2026-9597
- EPSS 0.14%
- Veröffentlicht 13.07.2026 08:17:36
- Zuletzt bearbeitet 13.07.2026 20:53:34
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via ...
CVE-2026-6850
- EPSS 0.24%
- Veröffentlicht 13.07.2026 08:13:02
- Zuletzt bearbeitet 13.07.2026 21:42:01
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via...
CVE-2026-10106
- EPSS 0.18%
- Veröffentlicht 13.07.2026 08:09:58
- Zuletzt bearbeitet 13.07.2026 21:42:24
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel ...
CVE-2026-10085
- EPSS 0.17%
- Veröffentlicht 13.07.2026 08:05:42
- Zuletzt bearbeitet 14.07.2026 13:19:08
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support group synchronization, which allows an ordinary group or direct message member...
CVE-2026-9708
- EPSS 0.21%
- Veröffentlicht 13.07.2026 08:00:10
- Zuletzt bearbeitet 13.07.2026 20:39:47
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts...
CVE-2026-10103
- EPSS 0.15%
- Veröffentlicht 13.07.2026 07:57:11
- Zuletzt bearbeitet 14.07.2026 15:16:54
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows an authenticated remote cluster to modify or delete posts authored by local users or ot...