Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 435

All 435 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE ID Title CVSS Severity Published
CVE-2026-75587 Plaintext pre-auth secret exposure via Desktop App diagnostics report CWE-200 3.6 Low 2026-08-17
CVE-2026-9693 Mattermost thread memberships persist after team removal, exposing private channel thread metadata on re-invite CWE-459 3.5 Low 2026-08-17
CVE-2026-9859 Mattermost Boards plugin didn’t enforce role-based authorization on board channel link allowing board editors to expose boards to arbitrary channels CWE-863 6.5 Medium 2026-08-17
CVE-2026-9816 Insufficient server-side validation of board member role fields permits privilege escalation CWE-863 8.3 High 2026-08-17
CVE-2026-10080 Boards plugin panics on WebSocket command with non-string field types CWE-704 6.5 Medium 2026-08-17
CVE-2026-10527 Boards plugin retains Board Admin rights for users demoted to System Guest CWE-863 6.3 Medium 2026-08-17
CVE-2026-15754 Missing per-channel team-scope check in ABAC access control policy unassign allows cross-team policy removal CWE-863 4.2 Medium 2026-08-17
CVE-2026-16044 Insufficient validation of guest board admin privileges on archive import CWE-863 3.9 Medium 2026-08-17
CVE-2026-16045 Delegated OAuth tokens could revoke unrelated OAuth application authorizations CWE-863 2.7 Medium 2026-08-17
CVE-2026-16049 _GitLab Plugin allows cross-channel post injection and phishing via missing channel permission checks in issue API endpoints_ CWE-862 3.9 Medium 2026-08-17
CVE-2026-16047 Board channel linking without read channel permission validation CWE-862 4.3 Medium 2026-08-17
CVE-2026-16046 Missing run-state validation on finished playbook runs CWE-863 3.5 Medium 2026-08-17
CVE-2026-16048 Channel member roles accept out-of-scope roles CWE-863 6.3 Medium 2026-08-17
CVE-2026-14298 Denial of service via resource exhaustion in Mattermost CWE-409 6.5 Medium 2026-08-13
CVE-2026-7521 SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory CWE-22 5.5 Medium 2026-07-28
CVE-2026-10819 Mattermost Server Denial of Service via Animated GIF Emoji Upload CWE-409 6.5 Medium 2026-07-27
CVE-2026-10600 Denial of service via unbounded document content extraction in Mattermost Server CWE-770 4.3 Medium 2026-07-27
CVE-2026-8075 Posting a malicious markdown image crashes the Mattermost Desktop App CWE-754 6.5 Medium 2026-07-17
CVE-2026-9602 Mattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methods CWE-400 5.7 Medium 2026-07-17
CVE-2026-6541 Unscoped updates to other playbooks' metric configuration CWE-639 4.3 Medium 2026-07-13
CVE-2026-9820 Mattermost schemes teams endpoint exposes private team invite IDs CWE-862 3.8 Low 2026-07-13
CVE-2026-9824 Remote cluster metadata enumeration via /share-channel autocomplete CWE-862 4.3 Medium 2026-07-13
CVE-2026-9597 Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint CWE-305 5.4 Medium 2026-07-13
CVE-2026-6850 Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost CWE-1333 6.5 Medium 2026-07-13
CVE-2026-10106 Unauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in Mattermost CWE-863 6.5 Medium 2026-07-13
CVE-2026-10085 Ordinary group/direct message member can enable group_constrained and remove all channel participants CWE-862 5.4 Medium 2026-07-13
CVE-2026-9708 Incoming webhook user attribution via unvalidated webhook owner CWE-639 4.9 Medium 2026-07-13
CVE-2026-10103 Authenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared channels CWE-639 4.3 Medium 2026-07-13
CVE-2026-9571 Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in Mattermost CWE-305 5.9 Medium 2026-07-13
CVE-2026-4339 SSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP server CWE-918 6.5 Medium 2026-06-26

All 435 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.