CVEs we hold for Mattermost
Records whose assigning authority named Mattermost as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9859Mattermost Boards plugin didn’t enforce role-based authorization on board channel link allowing board editors to expose…Mattermost
CVE-2026-9816Insufficient server-side validation of board member role fields permits privilege escalationMattermost
CVE-2026-9812Missing property field ownership validation in Playbooks run property update endpointMattermost
CVE-2026-9699Mattermost Agents plugin logs unsanitized OpenAI API keys on authentication errorsMattermost
CVE-2026-9693Mattermost thread memberships persist after team removal, exposing private channel thread metadata on re-inviteMattermost
CVE-2026-9602Mattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methodsMattermost
CVE-2026-9597Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpointMattermost
CVE-2026-9571Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in MattermostMattermost
CVE-2026-8823User Manager can demote bot accounts to guest without bot-management permissionMattermost
CVE-2026-86348MS Calendar plugin: unrecovered handler panics from malformed post-action requests could crash the plugin processMattermost
CVE-2026-7521SAML certificate deletion allows path traversal to delete arbitrary files outside the config directoryMattermost
CVE-2026-7387Mattermost group syncable endpoints allow privilege escalation via scheme_adminMattermost
CVE-2026-6961CVE-2026-6961: Path traversal via unsanitized FileInfo.Name in Mattermost federation syncMattermost
CVE-2026-6957Path traversal in Mattermost Legal Hold plugin via unsanitized file name from federated peer allows arbitrary file…Mattermost
CVE-2026-6850Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in MattermostMattermost
CVE-2026-6689*Missing* {{invite_user}} *permission check on team creation allows unprivileged users to set open-invite and…Mattermost
CVE-2026-6673Mattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud installMattermost
CVE-2026-6517Mattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passedMattermost
CVE-2026-6347Mattermost Calls plugin exposes TURN server credentials in plaintext in support packetsMattermost
CVE-2026-6343Mattermost Playbooks Plugin fails to enforce view permissions in list endpoints, allowing unauthorized access to public…Mattermost
CVE-2026-6334OAuth authorization code client binding not enforced during token redemption in MattermostMattermost
CVE-2026-6046Plugin bot username conflict allows user account to be used as bot identity in Mattermost ServerMattermost
CVE-2026-5740Unauthenticated WebSocket binary frame causes denial of service in Mattermost ServerMattermost
CVE-2026-5163Missing authorization check in AI message rewrite endpoint allows access to private thread contentMattermost
CVE-2026-5139GitLab Plugin Allows Non-Admin Users to Modify Default Instance ConfigurationMattermost
CVE-2026-4858Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.Mattermost
CVE-2026-4643Calling window.close() from server-side content causes crash in the Mattermost Desktop AppMattermost
CVE-2026-4286Playbooks Plugin fails to validate team transfers, allowing unauthorized removal of member access via playbook updateMattermost
CVE-2026-4274Insufficient authorization in shared channel membership sync grants team-level access instead of channel-level accessMattermost
CVE-2026-4054SVG content served through Mattermost image proxy despite Content-Type restrictions causes client-side denial of serviceMattermost
CVE-2026-3524Authorization Bypass in Mattermost Legal Hold Plugin Due to Missing Return After Permission CheckMattermost
CVE-2026-3473Improper file ownership validation in the Boards API allows unauthorised file accessMattermost
CVE-2026-3471Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop AppMattermost
CVE-2026-3433Mattermost fails to scope role_updated websocket events to authorized team and channel membersMattermost
CVE-2026-3117Instance and webhook GitLab plugin commands were able to be run by non-admin usersMattermost
CVE-2026-3113mmctl export download command doesn’t restrict permissions to created file to file ownerMattermost
CVE-2026-28759Insufficient authorization in shared channel membership sync allows remote cluster to remove users from arbitrary…Mattermost
CVE-2026-28736Focalboard IDOR in file content endpoint allows cross-user file access (unsupported product, no fix)Mattermost Focalboard
CVE-2026-27769Connected Workspaces: Malicious remote server can manipulate arbitrary user's statusMattermost
CVE-2026-2578Information Disclosure via WebSocket Event When Deleting Unrevealed Burn on Read PostsMattermost
CVE-2026-25773Focalboard Second-Order SQL Injection in category reorder endpoint allows data exfiltration (unsupported product, no…Mattermost Focalboard
CVE-2026-2476MS Teams plugin sensitive config values not properly masked in support packetsMattermost
CVE-2026-24661Unbounded Request Body Read in MS Teams Plugin {{/changes}} Webhook EndpointMattermost
CVE-2026-2461Missing authorization check allows unauthorized modification of other users' comments on a boardMattermost
CVE-2026-2299Improper Access Control in Mattermost Google Drive Plugin File Creation EndpointMattermost Google Drive Plugin
CVE-2026-22892Insufficient Authorization in Mattermost Jira Plugin Allows Unauthorized Access to Post AttachmentsMattermost
CVE-2026-21388Unbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook EndpointMattermost
CVE-2026-1628Mattermost allows external websites to open within the app, exposing preload functionality to non-trusted sites.Mattermost
CVE-2026-16049_GitLab Plugin allows cross-channel post injection and phishing via missing channel permission checks in issue API…Mattermost
CVE-2026-16045Delegated OAuth tokens could revoke unrelated OAuth application authorizationsMattermost
CVE-2026-15814Uploading a crafted image causes excessive memory allocation in the Mattermost ServerMattermost
CVE-2026-15754Missing per-channel team-scope check in ABAC access control policy unassign allows cross-team policy removalMattermost
CVE-2026-14298Boards archive import endpoint allows resource exhaustion via zip bomb and file size limit bypass in MattermostMattermost
CVE-2026-13426Client4 fails to validate path parametersMattermost github.com/mattermost/mattermost/server/public
CVE-2026-12985Mattermost DCR redirect URI allowlist bypass via improper URL component validationMattermost
CVE-2026-11993Fix authenticated members disabling file content indexing server-wide via extraction pool exhaustionMattermost
CVE-2026-10600Denial of service via unbounded document content extraction in Mattermost ServerMattermost
CVE-2026-10556Unauthenticated webhook request with null notification entry could crash the Microsoft Calendar plugin.Mattermost
CVE-2026-1046Arbitrary application execution via unvalidated server-controlled URLs in Help menuMattermost
CVE-2026-10106Unauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in…Mattermost
CVE-2026-10103Authenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared…Mattermost
CVE-2026-10085Ordinary group/direct message member can enable group_constrained and remove all channel participantsMattermost
CVE-2026-0999Authentication bypass via userID login when email and username login are disabledMattermost
CVE-2026-0998Mattermost Zoom Plugin allows unauthorized meeting creation and post modification via insufficient API access controlsMattermost
CVE-2025-9076Mattermost Server exposes sensitive user credentials during shared channel membership synchronizationMattermost
CVE-2025-8285Unauthorized Channel Subscription Creation in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-8023Path Traversal in Template Upload Allows Uploading Files Outside Target DirectoryMattermost
CVE-2025-54525Unexpected input to Create Channel Subscription endpoint causes DoS in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-54478Unauthenticated Channel Subscription Edit in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-54463Unexpected Input to Cloud Webhook endpoint Causes DoS in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-54458Unauthorized Subscription Creation to Confluence Space in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-53971Channel and Team Membership APIs inadvertently allow loss of Member privileges.Mattermost
CVE-2025-53910Unauthorized Channel Subscription Edit in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-53857Lack of Authorization on Get Channel Subscriptions for Autocomplete in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-53514Unexpected Input to Server Webhook endpoint Causes DoS in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-52931Unexpected input to Update Channel Subscription endpoint causes DoS in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-49221Unauthenticated Access to Channel Subscription in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-48731Unauthorized Subscription Edit to Confluence Space in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-47871Mattermost Playbooks exposes private channel metadata to unauthorized users via run metadata APIMattermost
CVE-2025-46702Mattermost Playbooks allows privilege escalation through improper access control in playbook run participant managementMattermost
CVE-2025-44004Unauthenticated Channel Subscription Creation in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-44001Unauthorized Channel Subscription Read in Mattermost Confluence PluginMattermost Confluence Plugin
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.