Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 422

All 422 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumeration (CWE) vulnerability data specifically for the Mattermost open-source collaboration platform. It compiles a comprehensive collection of security flaws, including those related to access control, cross-site scripting, and remote code execution, affecting various versions of the software. The database covers vulnerability records from the initial release of Mattermost up to the most recent publicly disclosed incidents, ensuring a complete historical overview of security issues. Visitors can use this resource to track the vendor’s advisory history, observing how promptly and effectively the development team responds to emerging threats. Users can also analyze the evolution of specific weakness classes within the Mattermost codebase to identify recurring patterns or systemic architectural vulnerabilities. Furthermore, this aggregation allows security professionals and administrators to look up a product’s vulnerability history, providing critical context for risk assessment and patch management decisions. By centralizing these disparate data points, the page serves as a vital reference for evaluating the overall security posture of the Mattermost ecosystem. This information is essential for maintaining secure deployments and understanding the long-term remediation efforts undertaken by the maintainers. The data is strictly factual, focusing on technical details and timeline verification rather than promotional content.

Vendor: Mattermost

CVE IDTitleCVSSSeverityPublished
CVE-2026-6689 *Missing* {{invite_user}} *permission check on team creation allows unprivileged users to set open-invite and allowed-domains team settings* CWE-862 4.3 Medium2026-06-12
CVE-2026-7184 Mattermost Remote Cluster PATCH API Leaks Authentication Tokens CWE-201 6.5 Medium2026-06-12
CVE-2026-6739 Mattermost: Delegated admins could patch protected default system roles CWE-863 6.7 Medium2026-06-12
CVE-2026-3433 Mattermost fails to scope role_updated websocket events to authorized team and channel members CWE-200 4.3 Medium2026-06-12
CVE-2026-6957 Path traversal in Mattermost Legal Hold plugin via unsanitized file name from federated peer allows arbitrary file write. CWE-22 8.0 High2026-05-27
CVE-2026-4915 Server panic via outgoing webhook responses CWE-754 6.5 Medium2026-05-25
CVE-2026-28735 GitHub OAuth Scope Validation CWE-863 5.4 Medium2026-05-22
CVE-2026-4635 Persistent notification timing attack causing server denial of service CWE-362 6.5 Medium2026-05-22
CVE-2026-3473 Improper file ownership validation in the Boards API allows unauthorised file access CWE-639 5.9 Medium2026-05-22
CVE-2026-4646 Insufficient input validation in GitHub plugin API causes denial of service CWE-1287 4.3 Medium2026-05-22
CVE-2026-3636 Sanitize team member data returned by API CWE-200 4.3 Medium2026-05-22
CVE-2026-5740 Unauthenticated WebSocket binary frame causes denial of service in Mattermost Server CWE-789 7.5 High2026-05-22
CVE-2026-5308 Missing request body size limits on Zoom plugin HTTP endpoints CWE-400 4.9 Medium2026-05-22
CVE-2026-5755 Denial of service via crafted TIFF file upload CWE-400 6.5 Medium2026-05-22
CVE-2026-22880 Mobile SSO authentication flow allows credential theft via malicious server CWE-352 6.1 Medium2026-05-21
CVE-2026-4858 Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token. CWE-22 8.0 High2026-05-21
CVE-2026-4055 Insufficient permission validation on cross-team playbook run creation CWE-863 4.3 Medium2026-05-21
CVE-2026-3471 Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop App CWE-939 6.5 Medium2026-05-18
CVE-2026-4643 Calling window.close() from server-side content causes crash in the Mattermost Desktop App CWE-754 3.5 Low2026-05-18
CVE-2026-6333 SSRF via Host Header Spoofing in Custom Slash Commands CWE-918 3.5 Low2026-05-18
CVE-2026-6345 Prevent password disclosure and force reset during Slack import CWE-522 6.5 Medium2026-05-18
CVE-2026-6346 Sensitive credentials exposed in plaintext in Mattermost support packets CWE-200 8.7 High2026-05-18
CVE-2026-28732 Slash command trigger-word update allowed command hijacking CWE-863 4.3 Medium2026-05-18
CVE-2026-6343 Mattermost Playbooks Plugin fails to enforce view permissions in list endpoints, allowing unauthorized access to public playbooks CWE-863 4.3 Medium2026-05-18
CVE-2026-6347 Mattermost Calls plugin exposes TURN server credentials in plaintext in support packets CWE-200 7.6 High2026-05-18
CVE-2026-5163 Missing authorization check in AI message rewrite endpoint allows access to private thread content CWE-862 6.5 Medium2026-05-18
CVE-2026-3117 Instance and webhook GitLab plugin commands were able to be run by non-admin users CWE-862 6.5 Medium2026-05-18
CVE-2026-4286 Playbooks Plugin fails to validate team transfers, allowing unauthorized removal of member access via playbook update CWE-863 3.1 Low2026-05-18
CVE-2026-6339 Missing request origin validation on burn-on-read reveal endpoint CWE-346 4.3 Medium2026-05-18
CVE-2026-6340 Memory Exhaustion via Malicious 7zip File Upload CWE-789 4.3 Medium2026-05-18

All 422 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.