github.com/mattermost/mattermost-server vulnerabilities
CVEs whose affected-version data names the github.com/mattermost/mattermost-server package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
13 CVEsRSS
CVE-2026-6673Medium· 6.4Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue share…
Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret
CVE-2026-6062Medium· 6.4Mattermost doesn't validate channel ownership of an existing subscription before applying edits
Mattermost doesn't validate channel ownership of an existing subscription before applying edits
CVE-2026-9162Medium· 4.3Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation
Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation
CVE-2026-8074Low· 3.8Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
CVE-2026-5139Medium· 5.4Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler
Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler
CVE-2026-3433Medium· 4.3Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
CVE-2026-6739Medium· 6.7Mattermost doesn't require system-level permission when patching protected default system roles
Mattermost doesn't require system-level permission when patching protected default system roles
CVE-2026-6689Medium· 4.3Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
CVE-2026-7184Medium· 6.5Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
CVE-2026-6961High· 7.6Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
CVE-2026-7387High· 8.8Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
CVE-2026-6046Medium· 5.3Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
CVE-2025-32093Medium· 4.7Mattermost Fails to Restrict Certain Operations on System Admins
Mattermost Fails to Restrict Certain Operations on System Admins