vciy

CVEs we hold for Mattermost

Records whose assigning authority named Mattermost as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9859Mattermost Boards plugin didn’t enforce role-based authorization on board channel link allowing board editors to expose…Mattermost
CVE-2026-9824Remote cluster metadata enumeration via /share-channel autocompleteMattermost
CVE-2026-9820Mattermost schemes teams endpoint exposes private team invite IDsMattermost
CVE-2026-9816Insufficient server-side validation of board member role fields permits privilege escalationMattermost
CVE-2026-9812Missing property field ownership validation in Playbooks run property update endpointMattermost
CVE-2026-9708Incoming webhook user attribution via unvalidated webhook ownerMattermost
CVE-2026-9699Mattermost Agents plugin logs unsanitized OpenAI API keys on authentication errorsMattermost
CVE-2026-9693Mattermost thread memberships persist after team removal, exposing private channel thread metadata on re-inviteMattermost
CVE-2026-9602Mattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methodsMattermost
CVE-2026-9597Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpointMattermost
CVE-2026-9571Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in MattermostMattermost
CVE-2026-9162Global session revocation does not invalidate active WebSocket connectionsMattermost
CVE-2026-91181Data Retention Teams Endpoint Leaks Private Team Invite IDMattermost
CVE-2026-8823User Manager can demote bot accounts to guest without bot-management permissionMattermost
CVE-2026-8821Playbooks run owner channel membership permission bypassMattermost
CVE-2026-8683Overly long URLs crash the Mattermost Desktop AppMattermost
CVE-2026-86349Mattermost Server Algorithmic DoS via Unbounded Markdown Block NestingMattermost
CVE-2026-86348MS Calendar plugin: unrecovered handler panics from malformed post-action requests could crash the plugin processMattermost
CVE-2026-82920Mattermost ABAC parent policy bypass via policy update endpointMattermost
CVE-2026-8075Posting a malicious markdown image crashes the Mattermost Desktop AppMattermost
CVE-2026-8074Improper Permission Check Allows User Manager to Deactivate Bot AccountsMattermost
CVE-2026-75588Mattermost Desktop App plugin popout scheme validation bypassMattermost
CVE-2026-75587Plaintext pre-auth secret exposure via Desktop App diagnostics reportMattermost
CVE-2026-7521SAML certificate deletion allows path traversal to delete arbitrary files outside the config directoryMattermost
CVE-2026-75025Mattermost Desktop local network access from server-rendered contentMattermost
CVE-2026-7387Mattermost group syncable endpoints allow privilege escalation via scheme_adminMattermost
CVE-2026-7184Mattermost Remote Cluster PATCH API Leaks Authentication TokensMattermost
CVE-2026-6961CVE-2026-6961: Path traversal via unsanitized FileInfo.Name in Mattermost federation syncMattermost
CVE-2026-6957Path traversal in Mattermost Legal Hold plugin via unsanitized file name from federated peer allows arbitrary file…Mattermost
CVE-2026-6850Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in MattermostMattermost
CVE-2026-6739Mattermost: Delegated admins could patch protected default system rolesMattermost
CVE-2026-6689*Missing* {{invite_user}} *permission check on team creation allows unprivileged users to set open-invite and…Mattermost
CVE-2026-6673Mattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud installMattermost
CVE-2026-6541Unscoped updates to other playbooks' metric configurationMattermost
CVE-2026-6517Mattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passedMattermost
CVE-2026-6347Mattermost Calls plugin exposes TURN server credentials in plaintext in support packetsMattermost
CVE-2026-6346Sensitive credentials exposed in plaintext in Mattermost support packetsMattermost
CVE-2026-6345Prevent password disclosure and force reset during Slack importMattermost
CVE-2026-6343Mattermost Playbooks Plugin fails to enforce view permissions in list endpoints, allowing unauthorized access to public…Mattermost
CVE-2026-6342Group prefix matching bypass for subscriptionsMattermost
CVE-2026-6341Incomplete group locking implementationMattermost
CVE-2026-6340Memory Exhaustion via Malicious 7zip File UploadMattermost
CVE-2026-6339Missing request origin validation on burn-on-read reveal endpointMattermost
CVE-2026-6334OAuth authorization code client binding not enforced during token redemption in MattermostMattermost
CVE-2026-6333SSRF via Host Header Spoofing in Custom Slash CommandsMattermost
CVE-2026-6062IDOR in Jira plugin subscription edit endpointMattermost
CVE-2026-6046Plugin bot username conflict allows user account to be used as bot identity in Mattermost ServerMattermost
CVE-2026-5755Denial of service via crafted TIFF file uploadMattermost
CVE-2026-5740Unauthenticated WebSocket binary frame causes denial of service in Mattermost ServerMattermost
CVE-2026-5308Missing request body size limits on Zoom plugin HTTP endpointsMattermost
CVE-2026-5163Missing authorization check in AI message rewrite endpoint allows access to private thread contentMattermost
CVE-2026-5139GitLab Plugin Allows Non-Admin Users to Modify Default Instance ConfigurationMattermost
CVE-2026-5132Unbounded zlib decompression in Calls SDP WebSocket messagesMattermost
CVE-2026-4915Server panic via outgoing webhook responsesMattermost
CVE-2026-4858Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token.Mattermost
CVE-2026-4646Insufficient input validation in GitHub plugin API causes denial of serviceMattermost
CVE-2026-4643Calling window.close() from server-side content causes crash in the Mattermost Desktop AppMattermost
CVE-2026-4635Persistent notification timing attack causing server denial of serviceMattermost
CVE-2026-4339SSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP serverMattermost
CVE-2026-4286Playbooks Plugin fails to validate team transfers, allowing unauthorized removal of member access via playbook updateMattermost
CVE-2026-4274Insufficient authorization in shared channel membership sync grants team-level access instead of channel-level accessMattermost
CVE-2026-4273Insufficient token rotation validation in remote cluster invite confirmationMattermost
CVE-2026-4265Guest user can upload files without permission across teamsMattermost
CVE-2026-4055Insufficient permission validation on cross-team playbook run creationMattermost
CVE-2026-4054SVG content served through Mattermost image proxy despite Content-Type restrictions causes client-side denial of serviceMattermost
CVE-2026-4053post edit time limit is not enforced on some post update operationsMattermost
CVE-2026-3637Mattermost fails to enforce create_post permission when editing postsMattermost
CVE-2026-3636Sanitize team member data returned by APIMattermost
CVE-2026-3590Race Condition in Guest Magic Link Authentication Allows Token ReuseMattermost
CVE-2026-3524Authorization Bypass in Mattermost Legal Hold Plugin Due to Missing Return After Permission CheckMattermost
CVE-2026-3495Unescaped variables during error page compositionMattermost
CVE-2026-3473Improper file ownership validation in the Boards API allows unauthorised file accessMattermost
CVE-2026-3472Markdown image rendering bypass in AI bot tool result posts in MattermostMattermost
CVE-2026-3471Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop AppMattermost
CVE-2026-3433Mattermost fails to scope role_updated websocket events to authorized team and channel membersMattermost
CVE-2026-3117Instance and webhook GitLab plugin commands were able to be run by non-admin usersMattermost
CVE-2026-3116Improper Input Validation in Zoom Plugin Webhook HandlerMattermost
CVE-2026-3115Guest users can view group member IDs without respecting view restrictionsMattermost
CVE-2026-3114Zip Bomb Denial of Service via Unrestricted Archive DecompressionMattermost
CVE-2026-3113mmctl export download command doesn’t restrict permissions to created file to file ownerMattermost
CVE-2026-3112Arbitrary File Read via Advanced Logging Support PacketMattermost
CVE-2026-3109Missing timestamp validation in Zoom webhook handlerMattermost
CVE-2026-3108Terminal Escape Injection in mmctl Report Posts CommandMattermost
CVE-2026-28759Insufficient authorization in shared channel membership sync allows remote cluster to remove users from arbitrary…Mattermost
CVE-2026-28741CSRF Protection Bypass Allows Updating a User's Authentication MethodMattermost
CVE-2026-28736Focalboard IDOR in file content endpoint allows cross-user file access (unsupported product, no fix)Mattermost Focalboard
CVE-2026-28735GitHub OAuth Scope ValidationMattermost
CVE-2026-28732Slash command trigger-word update allowed command hijackingMattermost
CVE-2026-27769Connected Workspaces: Malicious remote server can manipulate arbitrary user's statusMattermost
CVE-2026-27659CSRF vulnerability in UpdateAccessControlPolicyActiveStatus endpointMattermost
CVE-2026-27656Account Takeover via Substring Matching in OpenID Connect AuthenticationMattermost
CVE-2026-26304Permission Bypass in Playbook Run CreationMattermost
CVE-2026-26246Memory Exhaustion via Malformed PSD File UploadMattermost
CVE-2026-26233Denial of Service via HTTP/2 single packet attack on login endpointMattermost
CVE-2026-26230Team Admin Privilege Escalation to Demote Members to GuestMattermost
CVE-2026-25783Denial of service via malformed User-Agent header in getBrowserVersionMattermost
CVE-2026-25780Memory Exhaustion via Malformed DOC File UploadMattermost
CVE-2026-2578Information Disclosure via WebSocket Event When Deleting Unrevealed Burn on Read PostsMattermost
CVE-2026-25773Focalboard Second-Order SQL Injection in category reorder endpoint allows data exfiltration (unsupported product, no…Mattermost Focalboard
CVE-2026-2476MS Teams plugin sensitive config values not properly masked in support packetsMattermost
CVE-2026-24692Guest users can bypass read permissions via search APIMattermost
CVE-2026-24661Unbounded Request Body Read in MS Teams Plugin {{/changes}} Webhook EndpointMattermost
CVE-2026-2463Unauthorized access to invite ID during team creationMattermost
CVE-2026-2462Admin RCE via Malicious Plugin Upload on CI Test InstancesMattermost
CVE-2026-2461Missing authorization check allows unauthorized modification of other users' comments on a boardMattermost
CVE-2026-2458Unauthorized channel enumeration in private teams after member removalMattermost
CVE-2026-2457WebSocket Message Spoofing via Permalink Embed ManipulationMattermost
CVE-2026-2456Denial of Service via Unbounded Memory Allocation in Integration ActionsMattermost
CVE-2026-2455SSRF bypass via IPv4-mapped IPv6 literalsMattermost
CVE-2026-2454DoS in Calls plugin via malformed msgpack in websocket request.Mattermost
CVE-2026-24458DoS attack via login attempts with multi-megabyte passwordsMattermost
CVE-2026-2325Improper Input Validation in MS Teams Meetings API HandlerMattermost
CVE-2026-2299Improper Access Control in Mattermost Google Drive Plugin File Creation EndpointMattermost Google Drive Plugin
CVE-2026-22892Insufficient Authorization in Mattermost Jira Plugin Allows Unauthorized Access to Post AttachmentsMattermost
CVE-2026-22880Mobile SSO authentication flow allows credential theft via malicious serverMattermost
CVE-2026-22545Password Change Bypass via Auth Switch EndpointMattermost
CVE-2026-21388Unbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook EndpointMattermost
CVE-2026-21386Private channel enumeration via /mute slash commandMattermost
CVE-2026-20796Time-of-check time-of-use vulnerability in common teams APIMattermost
CVE-2026-20719DoS via URL Previews Rendering Malicious SVGsMattermost
CVE-2026-1629Permalink Preview Information Disclosure After Permission RevocationMattermost
CVE-2026-1628Mattermost allows external websites to open within the app, exposing preload functionality to non-trusted sites.Mattermost
CVE-2026-16049_GitLab Plugin allows cross-channel post injection and phishing via missing channel permission checks in issue API…Mattermost
CVE-2026-16048Channel member roles accept out-of-scope rolesMattermost
CVE-2026-16047Board channel linking without read channel permission validationMattermost
CVE-2026-16046Missing run-state validation on finished playbook runsMattermost
CVE-2026-16045Delegated OAuth tokens could revoke unrelated OAuth application authorizationsMattermost
CVE-2026-16044Insufficient validation of guest board admin privileges on archive importMattermost
CVE-2026-15814Uploading a crafted image causes excessive memory allocation in the Mattermost ServerMattermost
CVE-2026-15754Missing per-channel team-scope check in ABAC access control policy unassign allows cross-team policy removalMattermost
CVE-2026-14344Inconsistent authorization checks in Mattermost Boards endpointsMattermost
CVE-2026-14298Boards archive import endpoint allows resource exhaustion via zip bomb and file size limit bypass in MattermostMattermost
CVE-2026-14259Board archive import bypasses team board creation permissionsMattermost
CVE-2026-13426Client4 fails to validate path parametersMattermost github.com/mattermost/mattermost/server/public
CVE-2026-13417Boards plugin denial of service via unvalidated block fields.propertiesMattermost
CVE-2026-12985Mattermost DCR redirect URI allowlist bypass via improper URL component validationMattermost
CVE-2026-12882Mattermost Markdown autolink parsing denial of serviceMattermost
CVE-2026-12284Mattermost Desktop App Missing IPC Sender Validation in Calls Leave HandlerMattermost
CVE-2026-11993Fix authenticated members disabling file content indexing server-wide via extraction pool exhaustionMattermost
CVE-2026-10819Mattermost Server Denial of Service via Animated GIF Emoji UploadMattermost
CVE-2026-10600Denial of service via unbounded document content extraction in Mattermost ServerMattermost
CVE-2026-10556Unauthenticated webhook request with null notification entry could crash the Microsoft Calendar plugin.Mattermost
CVE-2026-10542Playbooks channel action update validation issueMattermost
CVE-2026-10527Boards plugin retains Board Admin rights for users demoted to System GuestMattermost
CVE-2026-1046Arbitrary application execution via unvalidated server-controlled URLs in Help menuMattermost
CVE-2026-10106Unauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in…Mattermost
CVE-2026-10103Authenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared…Mattermost
CVE-2026-10085Ordinary group/direct message member can enable group_constrained and remove all channel participantsMattermost
CVE-2026-10080Boards plugin panics on WebSocket command with non-string field typesMattermost
CVE-2026-0999Authentication bypass via userID login when email and username login are disabledMattermost
CVE-2026-0998Mattermost Zoom Plugin allows unauthorized meeting creation and post modification via insufficient API access controlsMattermost
CVE-2026-0997Mattermost Zoom Plugin channel preference API lacks authorization checksMattermost
CVE-2025-9084Open redirect in OAuth loginMattermost
CVE-2025-9081IDOR in board file download allows any user to download any file by UUIDMattermost
CVE-2025-9079Admin RCE via prepackaged plugins by way of misconfigured imports directoryMattermost
CVE-2025-9078Weak cache keys lead to post IDOR and link preview poisoningMattermost
CVE-2025-9076Mattermost Server exposes sensitive user credentials during shared channel membership synchronizationMattermost
CVE-2025-9072One-Click Mattermost Account Takeover via Poisoned RelayState SAML ParameterMattermost
CVE-2025-8402Nil pointer dereference in bulk import crashes serverMattermost
CVE-2025-8285Unauthorized Channel Subscription Creation in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-8023Path Traversal in Template Upload Allows Uploading Files Outside Target DirectoryMattermost
CVE-2025-6465Path traversal in image upload with preview overwriteMattermost
CVE-2025-64641Mattermost Jira plugin crafted action leaks Jira issue detailsMattermost
CVE-2025-62690Open redirect in error page when link opened in new tabMattermost
CVE-2025-6233Arbitrary file read by system admin via path traversalMattermost
CVE-2025-6227Invite token is used as part of the secure communicationMattermost
CVE-2025-6226IDOR in CreatePost API allows for timeboxed message disclosureMattermost
CVE-2025-62190CSRF Allows Call Initiation and Message DeliveryMattermost
CVE-2025-59480Inadequate validation of SSO redirect credentials permits credential theftMattermost
CVE-2025-58084Mattermost Desktop App crashes when clicking on malformed external URLMattermost
CVE-2025-58075Arbitrary Mattermost Team can be joined by manipulating the SAML RelayStateMattermost
CVE-2025-58073Arbitrary Mattermost Team can be joined by manipulating the OAuth stateMattermost
CVE-2025-55074Channel member objects leak read statusMattermost
CVE-2025-55073MS Teams plugin OAuth allows editing arbitrary postsMattermost
CVE-2025-55070Lack of MFA enforcement in WebSocket connectionsMattermost
CVE-2025-55035Mattermost Desktop DoS when user has basic authentication server configuredMattermost
CVE-2025-54525Unexpected input to Create Channel Subscription endpoint causes DoS in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-54499Insecure string comparison enables timing attacksMattermost
CVE-2025-54478Unauthenticated Channel Subscription Edit in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-54463Unexpected Input to Cloud Webhook endpoint Causes DoS in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-54458Unauthorized Subscription Creation to Confluence Space in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-53971Channel and Team Membership APIs inadvertently allow loss of Member privileges.Mattermost
CVE-2025-53910Unauthorized Channel Subscription Edit in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-53857Lack of Authorization on Get Channel Subscriptions for Autocomplete in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-53514Unexpected Input to Server Webhook endpoint Causes DoS in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-52931Unexpected input to Update Channel Subscription endpoint causes DoS in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-49810Thread summarization allows persistent access to channelMattermost
CVE-2025-4981Path Traversal Leading to RCE by Any Authenticated Mattermost UserMattermost
CVE-2025-49222Mattermost Shared Channel Upload Type Validation BypassMattermost
CVE-2025-49221Unauthenticated Access to Channel Subscription in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-48731Unauthorized Subscription Edit to Confluence Space in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-47871Mattermost Playbooks exposes private channel metadata to unauthorized users via run metadata APIMattermost
CVE-2025-47870Team invite ID leaked to team admin with no member invite privilegesMattermost
CVE-2025-47700AI plugin APIs can be triggered using post actionsMattermost
CVE-2025-46702Mattermost Playbooks allows privilege escalation through improper access control in playbook run participant managementMattermost
CVE-2025-4573LDAP Injection in Mattermost Enterprise Edition When Using Active DirectoryMattermost
CVE-2025-44004Unauthenticated Channel Subscription Creation in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-44001Unauthorized Channel Subscription Read in Mattermost Confluence PluginMattermost Confluence Plugin
CVE-2025-41443Guest user can discover active public channelsMattermost
CVE-2025-41436Unauthorized access to archived channel content via threads interfaceMattermost

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.