Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 421

All 421 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumeration (CWE) vulnerability data specifically for the Mattermost open-source collaboration platform. It compiles a comprehensive collection of security flaws, including those related to access control, cross-site scripting, and remote code execution, affecting various versions of the software. The database covers vulnerability records from the initial release of Mattermost up to the most recent publicly disclosed incidents, ensuring a complete historical overview of security issues. Visitors can use this resource to track the vendor’s advisory history, observing how promptly and effectively the development team responds to emerging threats. Users can also analyze the evolution of specific weakness classes within the Mattermost codebase to identify recurring patterns or systemic architectural vulnerabilities. Furthermore, this aggregation allows security professionals and administrators to look up a product’s vulnerability history, providing critical context for risk assessment and patch management decisions. By centralizing these disparate data points, the page serves as a vital reference for evaluating the overall security posture of the Mattermost ecosystem. This information is essential for maintaining secure deployments and understanding the long-term remediation efforts undertaken by the maintainers. The data is strictly factual, focusing on technical details and timeline verification rather than promotional content.

Vendor: Mattermost

CVE IDTitleCVSSSeverityPublished
CVE-2026-26304 Permission Bypass in Playbook Run Creation CWE-863 4.3 Medium2026-03-16
CVE-2026-24692 Guest users can bypass read permissions via search API CWE-863 4.3 Medium2026-03-16
CVE-2026-22545 Password Change Bypass via Auth Switch Endpoint CWE-863 3.1 Low2026-03-16
CVE-2026-2455 SSRF bypass via IPv4-mapped IPv6 literals CWE-918 4.3 Medium2026-03-16
CVE-2026-21386 Private channel enumeration via /mute slash command CWE-203 4.3 Medium2026-03-16
CVE-2026-25780 Memory Exhaustion via Malformed DOC File Upload CWE-789 4.3 Medium2026-03-16
CVE-2026-4265 Guest user can upload files without permission across teams CWE-863 4.3 Medium2026-03-16
CVE-2026-25783 Denial of service via malformed User-Agent header in getBrowserVersion CWE-1287 4.3 Medium2026-03-16
CVE-2026-24458 DoS attack via login attempts with multi-megabyte passwords CWE-770 7.5 High2026-03-16
CVE-2026-2462 Admin RCE via Malicious Plugin Upload on CI Test Instances CWE-863 6.6 Medium2026-03-16
CVE-2026-2578 Information Disclosure via WebSocket Event When Deleting Unrevealed Burn on Read Posts CWE-201 4.3 Medium2026-03-16
CVE-2026-26246 Memory Exhaustion via Malformed PSD File Upload CWE-789 4.3 Medium2026-03-16
CVE-2026-2458 Unauthorized channel enumeration in private teams after member removal CWE-862 4.3 Medium2026-03-16
CVE-2026-2457 WebSocket Message Spoofing via Permalink Embed Manipulation CWE-346 4.3 Medium2026-03-16
CVE-2026-2461 Missing authorization check allows unauthorized modification of other users' comments on a board CWE-639 4.3 Medium2026-03-16
CVE-2026-2463 Unauthorized access to invite ID during team creation CWE-862 4.3 Medium2026-03-16
CVE-2026-2476 MS Teams plugin sensitive config values not properly masked in support packets CWE-200 7.6 High2026-03-16
CVE-2026-2456 Denial of Service via Unbounded Memory Allocation in Integration Actions CWE-789 5.3 Medium2026-03-16
CVE-2026-1628 Mattermost allows external websites to open within the app, exposing preload functionality to non-trusted sites. CWE-829 4.6 Medium2026-03-02
CVE-2025-14573 Team Admin Bypass of Invite Permissions via allow_open_invite Field CWE-862 3.8 Low2026-02-16
CVE-2026-1046 Arbitrary application execution via unvalidated server-controlled URLs in Help menu CWE-939 7.6 High2026-02-16
CVE-2025-14350 Information disclosure via channel mentions in posts CWE-862 4.3 Medium2026-02-16
CVE-2025-13821 User profile update exposes password hash and MFA secrets CWE-200 5.7 Medium2026-02-16
CVE-2026-0997 Mattermost Zoom Plugin channel preference API lacks authorization checks CWE-863 4.3 Medium2026-02-16
CVE-2026-0998 Mattermost Zoom Plugin allows unauthorized meeting creation and post modification via insufficient API access controls CWE-862 4.3 Medium2026-02-16
CVE-2026-0999 Authentication bypass via userID login when email and username login are disabled CWE-303 5.4 Medium2026-02-16
CVE-2026-20796 Time-of-check time-of-use vulnerability in common teams API CWE-367 3.1 Low2026-02-13
CVE-2026-22892 Insufficient Authorization in Mattermost Jira Plugin Allows Unauthorized Access to Post Attachments CWE-863 4.3 Medium2026-02-13
CVE-2025-14435 Application-Level DoS via infinite re-render loop in user profile handling CWE-770 6.8 Medium2026-01-16
CVE-2025-14822 DoS from quadratic complexity in model.ParseHashtags CWE-407 3.1 Low2026-01-16

All 421 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.