Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 435

All 435 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE ID Title CVSS Severity Published
CVE-2026-9699 Mattermost Agents plugin logs unsanitized OpenAI API keys on authentication errors CWE-532 6.8 Medium 2026-06-26
CVE-2026-3472 Markdown image rendering bypass in AI bot tool result posts in Mattermost CWE-693 3.5 Low 2026-06-26
CVE-2026-8823 User Manager can demote bot accounts to guest without bot-management permission CWE-863 3.8 Low 2026-06-22
CVE-2026-6062 IDOR in Jira plugin subscription edit endpoint CWE-639 6.4 Medium 2026-06-22
CVE-2026-6673 Mattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud install CWE-306 6.4 Medium 2026-06-22
CVE-2026-8074 Improper Permission Check Allows User Manager to Deactivate Bot Accounts CWE-863 3.8 Low 2026-06-22
CVE-2026-9162 Global session revocation does not invalidate active WebSocket connections CWE-613 4.3 Medium 2026-06-22
CVE-2026-5139 GitLab Plugin Allows Non-Admin Users to Modify Default Instance Configuration CWE-862 5.4 Medium 2026-06-22
CVE-2026-8683 Overly long URLs crash the Mattermost Desktop App CWE-770 6.5 Medium 2026-06-15
CVE-2026-6517 Mattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passed CWE-522 6.3 Medium 2026-06-15
CVE-2026-6961 CVE-2026-6961: Path traversal via unsanitized FileInfo.Name in Mattermost federation sync CWE-22 7.6 High 2026-06-12
CVE-2026-7387 Mattermost group syncable endpoints allow privilege escalation via scheme_admin CWE-863 8.8 High 2026-06-12
CVE-2026-6046 Plugin bot username conflict allows user account to be used as bot identity in Mattermost Server CWE-200 5.3 Medium 2026-06-12
CVE-2026-6689 *Missing* {{invite_user}} *permission check on team creation allows unprivileged users to set open-invite and allowed-domains team settings* CWE-862 4.3 Medium 2026-06-12
CVE-2026-7184 Mattermost Remote Cluster PATCH API Leaks Authentication Tokens CWE-201 6.5 Medium 2026-06-12
CVE-2026-6739 Mattermost: Delegated admins could patch protected default system roles CWE-863 6.7 Medium 2026-06-12
CVE-2026-3433 Mattermost fails to scope role_updated websocket events to authorized team and channel members CWE-200 4.3 Medium 2026-06-12
CVE-2026-6957 Path traversal in Mattermost Legal Hold plugin via unsanitized file name from federated peer allows arbitrary file write. CWE-22 8.0 High 2026-05-27
CVE-2026-4915 Server panic via outgoing webhook responses CWE-754 6.5 Medium 2026-05-25
CVE-2026-28735 GitHub OAuth Scope Validation CWE-863 5.4 Medium 2026-05-22
CVE-2026-4635 Persistent notification timing attack causing server denial of service CWE-362 6.5 Medium 2026-05-22
CVE-2026-3473 Improper file ownership validation in the Boards API allows unauthorised file access CWE-639 5.9 Medium 2026-05-22
CVE-2026-4646 Insufficient input validation in GitHub plugin API causes denial of service CWE-1287 4.3 Medium 2026-05-22
CVE-2026-3636 Sanitize team member data returned by API CWE-200 4.3 Medium 2026-05-22
CVE-2026-5740 Unauthenticated WebSocket binary frame causes denial of service in Mattermost Server CWE-789 7.5 High 2026-05-22
CVE-2026-5308 Missing request body size limits on Zoom plugin HTTP endpoints CWE-400 4.9 Medium 2026-05-22
CVE-2026-5755 Denial of service via crafted TIFF file upload CWE-400 6.5 Medium 2026-05-22
CVE-2026-22880 Mobile SSO authentication flow allows credential theft via malicious server CWE-352 6.1 Medium 2026-05-21
CVE-2026-4858 Path traversal in integration action URL leading to arbitrary API execution via system admin’s auth token. CWE-22 8.0 High 2026-05-21
CVE-2026-4055 Insufficient permission validation on cross-team playbook run creation CWE-863 4.3 Medium 2026-05-21

All 435 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.