Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 421

All 421 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumeration (CWE) vulnerability data specifically for the Mattermost open-source collaboration platform. It compiles a comprehensive collection of security flaws, including those related to access control, cross-site scripting, and remote code execution, affecting various versions of the software. The database covers vulnerability records from the initial release of Mattermost up to the most recent publicly disclosed incidents, ensuring a complete historical overview of security issues. Visitors can use this resource to track the vendor’s advisory history, observing how promptly and effectively the development team responds to emerging threats. Users can also analyze the evolution of specific weakness classes within the Mattermost codebase to identify recurring patterns or systemic architectural vulnerabilities. Furthermore, this aggregation allows security professionals and administrators to look up a product’s vulnerability history, providing critical context for risk assessment and patch management decisions. By centralizing these disparate data points, the page serves as a vital reference for evaluating the overall security posture of the Mattermost ecosystem. This information is essential for maintaining secure deployments and understanding the long-term remediation efforts undertaken by the maintainers. The data is strictly factual, focusing on technical details and timeline verification rather than promotional content.

Vendor: Mattermost

CVE IDTitleCVSSSeverityPublished
CVE-2026-7521 SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory CWE-22 5.5 Medium2026-07-28
CVE-2026-10819 Mattermost Server Denial of Service via Animated GIF Emoji Upload CWE-409 6.5 Medium2026-07-27
CVE-2026-10600 Denial of service via unbounded document content extraction in Mattermost Server CWE-770 4.3 Medium2026-07-27
CVE-2026-8075 Posting a malicious markdown image crashes the Mattermost Desktop App CWE-754 6.5 Medium2026-07-17
CVE-2026-9602 Mattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methods CWE-400 5.7 Medium2026-07-17
CVE-2026-6541 Unscoped updates to other playbooks' metric configuration CWE-639 4.3 Medium2026-07-13
CVE-2026-9820 Mattermost schemes teams endpoint exposes private team invite IDs CWE-862 3.8 Low2026-07-13
CVE-2026-9824 Remote cluster metadata enumeration via /share-channel autocomplete CWE-862 4.3 Medium2026-07-13
CVE-2026-9597 Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint CWE-305 5.4 Medium2026-07-13
CVE-2026-6850 Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost CWE-1333 6.5 Medium2026-07-13
CVE-2026-10106 Unauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in Mattermost CWE-863 6.5 Medium2026-07-13
CVE-2026-10085 Ordinary group/direct message member can enable group_constrained and remove all channel participants CWE-862 5.4 Medium2026-07-13
CVE-2026-9708 Incoming webhook user attribution via unvalidated webhook owner CWE-639 4.9 Medium2026-07-13
CVE-2026-10103 Authenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared channels CWE-639 4.3 Medium2026-07-13
CVE-2026-9571 Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in Mattermost CWE-305 5.9 Medium2026-07-13
CVE-2026-4339 SSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP server CWE-918 6.5 Medium2026-06-26
CVE-2026-9699 Mattermost Agents plugin logs unsanitized OpenAI API keys on authentication errors CWE-532 6.8 Medium2026-06-26
CVE-2026-3472 Markdown image rendering bypass in AI bot tool result posts in Mattermost CWE-693 3.5 Low2026-06-26
CVE-2026-8823 User Manager can demote bot accounts to guest without bot-management permission CWE-863 3.8 Low2026-06-22
CVE-2026-6062 IDOR in Jira plugin subscription edit endpoint CWE-639 6.4 Medium2026-06-22
CVE-2026-6673 Mattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud install CWE-306 6.4 Medium2026-06-22
CVE-2026-8074 Improper Permission Check Allows User Manager to Deactivate Bot Accounts CWE-863 3.8 Low2026-06-22
CVE-2026-9162 Global session revocation does not invalidate active WebSocket connections CWE-613 4.3 Medium2026-06-22
CVE-2026-5139 GitLab Plugin Allows Non-Admin Users to Modify Default Instance Configuration CWE-862 5.4 Medium2026-06-22
CVE-2026-8683 Overly long URLs crash the Mattermost Desktop App CWE-770 6.5 Medium2026-06-15
CVE-2026-6517 Mattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passed CWE-522 6.3 Medium2026-06-15
CVE-2026-6961 CVE-2026-6961: Path traversal via unsanitized FileInfo.Name in Mattermost federation sync CWE-22 7.6 High2026-06-12
CVE-2026-7387 Mattermost group syncable endpoints allow privilege escalation via scheme_admin CWE-863 8.8 High2026-06-12
CVE-2026-6046 Plugin bot username conflict allows user account to be used as bot identity in Mattermost Server CWE-200 5.3 Medium2026-06-12
CVE-2026-6689 *Missing* {{invite_user}} *permission check on team creation allows unprivileged users to set open-invite and allowed-domains team settings* CWE-862 4.3 Medium2026-06-12

All 421 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.