mattermost

575 tracked vulnerabilities.

CVE-2026-27659 MEDIUM
Mattermost <= 11.4.0 - Access Control Policy Activation CSRF
Mar 25, 2026
CVSS 4.6
EPSS 0.00
CVE-2026-27656 MEDIUM
Account Takeover via Substring Matching in OpenID Connect Authentication
Mar 25, 2026
CVSS 5.7
EPSS 0.00
CVE-2026-26233 MEDIUM
Denial of Service via HTTP/2 single packet attack on login endpoint
Mar 25, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-20719 MEDIUM
DoS via URL Previews Rendering Malicious SVGs
Mar 25, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-2454 MEDIUM
DoS in Calls plugin via malformed msgpack in websocket request.
Mar 16, 2026
CVSS 5.8
EPSS 0.00
CVE-2026-26230 LOW
Team Admin Privilege Escalation to Demote Members to Guest
Mar 16, 2026
CVSS 3.8
EPSS 0.00
CVE-2026-1629 MEDIUM
Permalink Preview Information Disclosure After Permission Revocation
Mar 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-26304 MEDIUM
Permission Bypass in Playbook Run Creation
Mar 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-2455 MEDIUM
SSRF bypass via IPv4-mapped IPv6 literals
Mar 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-24692 MEDIUM
Guest users can bypass read permissions via search API
Mar 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-22545 LOW
Password Change Bypass via Auth Switch Endpoint
Mar 16, 2026
CVSS 3.1
EPSS 0.00
CVE-2026-21386 MEDIUM
Private channel enumeration via /mute slash command
Mar 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-4265 MEDIUM
Guest user can upload files without permission across teams
Mar 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-2578 MEDIUM
Information Disclosure via WebSocket Event When Deleting Unrevealed Burn on Read Posts
Mar 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-2476 HIGH
MS Teams plugin sensitive config values not properly masked in support packets
Mar 16, 2026
CVSS 7.6
EPSS 0.00
CVE-2026-2463 MEDIUM
Unauthorized access to invite ID during team creation
Mar 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-2462 MEDIUM
Admin RCE via Malicious Plugin Upload on CI Test Instances
Mar 16, 2026
CVSS 6.6
EPSS 0.00
CVE-2026-2461 MEDIUM
Missing authorization check allows unauthorized modification of other users' comments on a board
Mar 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-2458 MEDIUM
Unauthorized channel enumeration in private teams after member removal
Mar 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-2457 MEDIUM
WebSocket Message Spoofing via Permalink Embed Manipulation
Mar 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-2456 MEDIUM
Denial of Service via Unbounded Memory Allocation in Integration Actions
Mar 16, 2026
CVSS 5.3
EPSS 0.00
CVE-2026-26246 MEDIUM
Memory Exhaustion via Malformed PSD File Upload
Mar 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-25783 MEDIUM
Denial of service via malformed User-Agent header in getBrowserVersion
Mar 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-25780 MEDIUM
Memory Exhaustion via Malformed DOC File Upload
Mar 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-24458 HIGH
DoS attack via login attempts with multi-megabyte passwords
Mar 16, 2026
CVSS 7.5
EPSS 0.00