Mattermost是美国Mattermost公司开源的一个开源协作平台。 Mattermost存在信息泄露漏洞,该漏洞源于未能限制role_updated websocket事件广播至受影响的团队或频道成员,可能导致经过身份验证的具有访客级访问权限的攻击者通过websocket连接观察到其未加入的私有团队的权限方案更改通知。以下版本受到影响:11.6.1及之前的11.6.x版本、11.5.4及之前的11.5.x版本、10.11.15及之前的10.11.x版本和10.11.16及之前的10.11.x版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Mattermost | Mattermost | 11.6.0≤ 11.6.1 |
affected |
11.5.0≤ 11.5.4 |
affected | ||
10.11.0≤ 10.11.15 |
affected | ||
10.11.0≤ 10.11.16 |
affected | ||
11.7.0 |
unaffected | ||
11.6.2 |
unaffected | ||
11.5.5 |
unaffected | ||
10.11.16 |
unaffected | ||
| … +1 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost | 11.6.0 ~ 11.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7387 | 8.8 HIGH | Mattermost group syncable endpoints allow privilege escalation via scheme_admin |
| CVE-2026-6961 | 7.6 HIGH | CVE-2026-6961: Path traversal via unsanitized FileInfo.Name in Mattermost federation sync |
| CVE-2026-6739 | 6.7 MEDIUM | Mattermost: Delegated admins could patch protected default system roles |
| CVE-2026-7184 | 6.5 MEDIUM | Mattermost Remote Cluster PATCH API Leaks Authentication Tokens |
| CVE-2026-6046 | 5.3 MEDIUM | Plugin bot username conflict allows user account to be used as bot identity in Mattermost |
| CVE-2026-6689 | 4.3 MEDIUM | *Missing* {{invite_user}} *permission check on team creation allows unprivileged users to |
No comments yet