VulnSea

github.com/mattermost/mattermost-server vulnerabilities

CVEs whose affected-version data names the github.com/mattermost/mattermost-server package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

13 CVEsRSS

CVE-2026-6673Medium· 6.4
3mo ago

Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue share…

Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.30%via OSV
CVE-2026-6062Medium· 6.4
3mo ago

Mattermost doesn't validate channel ownership of an existing subscription before applying edits

Mattermost doesn't validate channel ownership of an existing subscription before applying edits

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.24%via OSV
CVE-2026-9162Medium· 4.3
3mo ago

Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation

Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.33%via OSV
CVE-2026-8074Low· 3.8
3mo ago

Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint

Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.32%via OSV
CVE-2026-5139Medium· 5.4
3mo ago

Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler

Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.29%via OSV
CVE-2026-3433Medium· 4.3
3mo ago

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.18%via OSV
CVE-2026-6739Medium· 6.7
3mo ago

Mattermost doesn't require system-level permission when patching protected default system roles

Mattermost doesn't require system-level permission when patching protected default system roles

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.26%via OSV
CVE-2026-6689Medium· 4.3
3mo ago

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.15%via OSV
CVE-2026-7184Medium· 6.5
3mo ago

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.26%via OSV
CVE-2026-6961High· 7.6
3mo ago

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

Twilightmattermost · github.com/mattermost/mattermost-serverEPSS 0.30%via OSV
CVE-2026-7387High· 8.8
3mo ago

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints

Twilightmattermost · github.com/mattermost/mattermost-serverEPSS 0.31%via OSV
CVE-2026-6046Medium· 5.3
3mo ago

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.19%via OSV
CVE-2025-32093Medium· 4.7
1y ago

Mattermost Fails to Restrict Certain Operations on System Admins

Mattermost Fails to Restrict Certain Operations on System Admins

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.24%via OSV
github.com/mattermost/mattermost-server vulnerabilities (CVEs) · VulnSea