Mattermost是美国Mattermost公司开源的一个开源协作平台。 Mattermost 11.7.6及之前的11.7.x版本、10.11.21及之前的10.11.x版本和11.8.3及之前的11.8.x版本存在授权问题漏洞,该漏洞源于在链接看板到频道前未验证用户是否具有该频道的读取权限,可能导致经过身份验证的攻击者通过创建、修补、导入或批量创建带有任意channelId的看板来发现同一团队中私有频道的成员。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Mattermost | Mattermost | 11.7.0≤ 11.7.6 |
affected |
10.11.0≤ 10.11.21 |
affected | ||
11.8.0≤ 11.8.3 |
affected | ||
11.9.0 |
unaffected | ||
11.7.7 |
unaffected | ||
10.11.22 |
unaffected | ||
11.8.4 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost | 11.7.0 ~ 11.7.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9816 | 8.3 HIGH | Insufficient server-side validation of board member role fields permits privilege escalati |
| CVE-2026-9859 | 6.5 MEDIUM | Mattermost Boards plugin didn’t enforce role-based authorization on board channel link all |
| CVE-2026-10080 | 6.5 MEDIUM | Boards plugin panics on WebSocket command with non-string field types |
| CVE-2026-10527 | 6.3 MEDIUM | Boards plugin retains Board Admin rights for users demoted to System Guest |
| CVE-2026-16048 | 6.3 MEDIUM | Channel member roles accept out-of-scope roles |
| CVE-2026-15754 | 4.2 MEDIUM | Missing per-channel team-scope check in ABAC access control policy unassign allows cross-t |
| CVE-2026-16044 | 3.9 LOW | Insufficient validation of guest board admin privileges on archive import |
| CVE-2026-16049 | 3.9 LOW | _GitLab Plugin allows cross-channel post injection and phishing via missing channel permis |
| CVE-2026-75587 | 3.6 LOW | Plaintext pre-auth secret exposure via Desktop App diagnostics report |
| CVE-2026-9693 | 3.5 LOW | Mattermost thread memberships persist after team removal, exposing private channel thread |
| CVE-2026-16046 | 3.5 LOW | Missing run-state validation on finished playbook runs |
| CVE-2026-16045 | 2.7 LOW | Delegated OAuth tokens could revoke unrelated OAuth application authorizations |
No comments yet