Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Mattermost — Vulnerabilities & Security Advisories 435

All 435 CVE vulnerabilities found in Mattermost, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Mattermost, focusing on Common Weakness Enumerations associated with the open-source team messaging platform. It collects a comprehensive range of security flaws, including authentication bypasses, injection vulnerabilities, and cross-site scripting issues, covering all recorded incidents from the product's inception through the current date. Visitors can utilize this resource to track vendor advisories as they are published, gain a deeper understanding of specific weakness classes and their implications for the software architecture, and examine the historical trend of security incidents affecting this particular product. The data is organized to facilitate security research, compliance auditing, and risk assessment for organizations deploying or evaluating Mattermost. By centralizing these records, the page aims to provide clarity on the security posture of the product over time, helping stakeholders identify recurring patterns in defect types and the effectiveness of mitigation strategies. The information presented here is derived from official vendor disclosures, third-party security reports, and publicly available vulnerability databases, ensuring a broad and accurate perspective on known security issues. This aggregation serves as a reference point for developers, security analysts, and system administrators who need to make informed decisions about patching, configuration hardening, and overall risk management for their Mattermost deployments.

Vendor: Mattermost

CVE ID Title CVSS Severity Published
CVE-2026-3109 Missing timestamp validation in Zoom webhook handler CWE-754 2.2 Low 2026-03-26
CVE-2026-3115 Guest users can view group member IDs without respecting view restrictions CWE-863 4.3 Medium 2026-03-26
CVE-2026-3114 Zip Bomb Denial of Service via Unrestricted Archive Decompression CWE-409 6.5 Medium 2026-03-26
CVE-2026-3116 Improper Input Validation in Zoom Plugin Webhook Handler CWE-400 4.9 Medium 2026-03-26
CVE-2026-3113 mmctl export download command doesn’t restrict permissions to created file to file owner CWE-732 5.0 Medium 2026-03-26
CVE-2026-3108 Terminal Escape Injection in mmctl Report Posts Command CWE-150 8.0 High 2026-03-26
CVE-2026-4274 Insufficient authorization in shared channel membership sync grants team-level access instead of channel-level access CWE-863 5.4 Medium 2026-03-26
CVE-2026-27659 CSRF vulnerability in UpdateAccessControlPolicyActiveStatus endpoint CWE-352 4.6 Medium 2026-03-25
CVE-2026-20719 DoS via URL Previews Rendering Malicious SVGs CWE-754 4.3 Medium 2026-03-25
CVE-2026-27656 Account Takeover via Substring Matching in OpenID Connect Authentication CWE-303 5.7 Medium 2026-03-25
CVE-2026-26233 Denial of Service via HTTP/2 single packet attack on login endpoint CWE-400 4.3 Medium 2026-03-25
CVE-2026-1629 Permalink Preview Information Disclosure After Permission Revocation CWE-672 4.3 Medium 2026-03-16
CVE-2026-26230 Team Admin Privilege Escalation to Demote Members to Guest CWE-863 3.8 Low 2026-03-16
CVE-2026-2454 DoS in Calls plugin via malformed msgpack in websocket request. CWE-1287 5.8 Medium 2026-03-16
CVE-2026-26304 Permission Bypass in Playbook Run Creation CWE-863 4.3 Medium 2026-03-16
CVE-2026-24692 Guest users can bypass read permissions via search API CWE-863 4.3 Medium 2026-03-16
CVE-2026-22545 Password Change Bypass via Auth Switch Endpoint CWE-863 3.1 Low 2026-03-16
CVE-2026-2455 SSRF bypass via IPv4-mapped IPv6 literals CWE-918 4.3 Medium 2026-03-16
CVE-2026-21386 Private channel enumeration via /mute slash command CWE-203 4.3 Medium 2026-03-16
CVE-2026-25780 Memory Exhaustion via Malformed DOC File Upload CWE-789 4.3 Medium 2026-03-16
CVE-2026-4265 Guest user can upload files without permission across teams CWE-863 4.3 Medium 2026-03-16
CVE-2026-25783 Denial of service via malformed User-Agent header in getBrowserVersion CWE-1287 4.3 Medium 2026-03-16
CVE-2026-24458 DoS attack via login attempts with multi-megabyte passwords CWE-770 7.5 High 2026-03-16
CVE-2026-2462 Admin RCE via Malicious Plugin Upload on CI Test Instances CWE-863 6.6 Medium 2026-03-16
CVE-2026-2578 Information Disclosure via WebSocket Event When Deleting Unrevealed Burn on Read Posts CWE-201 4.3 Medium 2026-03-16
CVE-2026-26246 Memory Exhaustion via Malformed PSD File Upload CWE-789 4.3 Medium 2026-03-16
CVE-2026-2458 Unauthorized channel enumeration in private teams after member removal CWE-862 4.3 Medium 2026-03-16
CVE-2026-2457 WebSocket Message Spoofing via Permalink Embed Manipulation CWE-346 4.3 Medium 2026-03-16
CVE-2026-2461 Missing authorization check allows unauthorized modification of other users' comments on a board CWE-639 4.3 Medium 2026-03-16
CVE-2026-2463 Unauthorized access to invite ID during team creation CWE-862 4.3 Medium 2026-03-16

All 435 known CVE vulnerabilities affecting Mattermost with full Chinese analysis, references, and POCs where available.