Mattermost是美国Mattermost公司开源的一个开源协作平台。 Mattermost 6.2.2及之前版本存在信息泄露漏洞,该漏洞源于生成诊断报告时未能隐藏预认证密钥,可能导致具有诊断报告或日志文件访问权限的本地攻击者通过检查服务器连接诊断输出获取明文预认证密钥。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Mattermost | Mattermost | ≤ 6.2.2 |
affected |
6.3.0 |
unaffected | ||
6.2.3.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Mattermost | Mattermost | 0 ~ 6.2.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9816 | 8.3 HIGH | Insufficient server-side validation of board member role fields permits privilege escalati |
| CVE-2026-10080 | 6.5 MEDIUM | Boards plugin panics on WebSocket command with non-string field types |
| CVE-2026-9859 | 6.5 MEDIUM | Mattermost Boards plugin didn’t enforce role-based authorization on board channel link all |
| CVE-2026-16048 | 6.3 MEDIUM | Channel member roles accept out-of-scope roles |
| CVE-2026-10527 | 6.3 MEDIUM | Boards plugin retains Board Admin rights for users demoted to System Guest |
| CVE-2026-16047 | 4.3 MEDIUM | Board channel linking without read channel permission validation |
| CVE-2026-15754 | 4.2 MEDIUM | Missing per-channel team-scope check in ABAC access control policy unassign allows cross-t |
| CVE-2026-16049 | 3.9 LOW | _GitLab Plugin allows cross-channel post injection and phishing via missing channel permis |
| CVE-2026-16044 | 3.9 LOW | Insufficient validation of guest board admin privileges on archive import |
| CVE-2026-16046 | 3.5 LOW | Missing run-state validation on finished playbook runs |
| CVE-2026-9693 | 3.5 LOW | Mattermost thread memberships persist after team removal, exposing private channel thread |
| CVE-2026-16045 | 2.7 LOW | Delegated OAuth tokens could revoke unrelated OAuth application authorizations |
No comments yet