VulnSea

mattermost has 60 CVEs on record between 2023 and 2026. Cadence is steady at roughly 20 per quarter. The busiest recent month was September 2026 with 19. The median CVSS is 5.2 (medium), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-862 (5) and CWE-409 (3). Most affected products: github.com/mattermost/mattermost/server/v8 (22), Mattermost (20), github.com/mattermost/mattermost-server (13).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.2
Publish → KEV
Last 90 days
20 prev 14

Products

  • github.com/mattermost/mattermost/server/v8 22
  • Mattermost 20
  • github.com/mattermost/mattermost-server 13
  • github.com/mattermost/mattermost-server/v6 2
  • github.com/mattermost/mattermost-plugin-playbooks 1
  • legal_hold 1
60
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

mattermost vulnerabilities

CVEs affecting mattermost, newest first. Open any entry for full detail, references, and exploit status.

60 CVEsRSS

CVE-2026-75588Low· 2.6
5d ago

Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insec…

Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal to the connected server, which allows a network-positioned attacker to load a plugin popout window over an insec…

SunlitMattermost · MattermostEPSS 0.17%via NVD
CVE-2026-12284Low· 3.7
5d ago

Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an …

Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a malicious or compromised Mattermost server (or a user with script access to a connected server view) to disconnect an …

SunlitMattermost · MattermostEPSS 0.13%via NVD
CVE-2026-75025Medium· 4.7
6d ago

Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources

Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. Thanks to game0v3r for contributing to this im…

SunlitMattermost · MattermostEPSS 0.15%via NVD
CVE-2026-91181Medium· 6.5
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data …

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data …

SunlitMattermost · MattermostEPSS 0.23%via NVD
CVE-2026-14259Medium· 4.3
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or P…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or P…

SunlitMattermost · MattermostEPSS 0.15%via NVD
CVE-2026-11993Medium· 4.3
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload …

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload …

SunlitMattermost · MattermostEPSS 0.21%via NVD
CVE-2026-9812Medium· 6.5
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run prope…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run prope…

SunlitMattermost · MattermostEPSS 0.21%via NVD
CVE-2026-8821High· 7.1
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrar…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrar…

TwilightMattermost · MattermostEPSS 0.17%via NVD
CVE-2026-5132Medium· 6.5
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service or crash server via sending many SDP me…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service or crash server via sending many SDP me…

SunlitMattermost · MattermostEPSS 0.24%via NVD
CVE-2026-15814Medium· 6.5
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause excessive server me…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause excessive server me…

SunlitMattermost · MattermostEPSS 0.24%via NVD
CVE-2026-14344Medium· 4.3
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-…

SunlitMattermost · MattermostEPSS 0.15%via NVD
CVE-2026-13417Medium· 4.3
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a board to crash th…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a board to crash th…

SunlitMattermost · MattermostEPSS 0.21%via NVD
CVE-2026-12882Medium· 4.3
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Markdown autolinks with unmatched trailing closing parentheses in linear time, which allows an authenticated user with permission…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Markdown autolinks with unmatched trailing closing parentheses in linear time, which allows an authenticated user with permission…

SunlitMattermost · MattermostEPSS 0.21%via NVD
CVE-2026-10556Medium· 5.3
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft…

SunlitMattermost · MattermostEPSS 0.25%via NVD
CVE-2026-10542Medium· 5.0
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel action ownership which allows channel managers to update actions in other channels via the channel action update endpo…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel action ownership which allows channel managers to update actions in other channels via the channel action update endpo…

SunlitMattermost · MattermostEPSS 0.13%via NVD
CVE-2026-12985Medium· 6.8
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a …

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a …

SunlitMattermost · MattermostEPSS 0.28%via NVD
CVE-2026-86349Medium· 4.3
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting depth in the server-side Markdown parser which allows an authenticated attacker to cause a denial of service (CPU res…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting depth in the server-side Markdown parser which allows an authenticated attacker to cause a denial of service (CPU res…

SunlitMattermost · MattermostEPSS 0.22%via NVD
CVE-2026-86348Medium· 4.3
1w ago

Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.

Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.. Mattermost Advisory ID: MMSA…

SunlitMattermost · MattermostEPSS 0.22%via NVD
CVE-2026-82920Medium· 5.5
1w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC …

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC …

SunlitMattermost · MattermostEPSS 0.15%via NVD
CVE-2026-14298Medium· 6.5
1mo ago

Boards archive import endpoint allows resource exhaustion via zip bomb and file size limit bypass in Mattermost

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler, which allows an auth…

SunlitMattermost · MattermostEPSS 0.24%via CVEORG
CVE-2026-6673Medium· 6.4
3mo ago

Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue share…

Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.30%via OSV
CVE-2026-6062Medium· 6.4
3mo ago

Mattermost doesn't validate channel ownership of an existing subscription before applying edits

Mattermost doesn't validate channel ownership of an existing subscription before applying edits

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.24%via OSV
CVE-2026-9162Medium· 4.3
3mo ago

Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation

Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.33%via OSV
CVE-2026-8074Low· 3.8
3mo ago

Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint

Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.32%via OSV
CVE-2026-5139Medium· 5.4
3mo ago

Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler

Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.29%via OSV
CVE-2026-3433Medium· 4.3
3mo ago

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.18%via OSV
CVE-2026-6739Medium· 6.7
3mo ago

Mattermost doesn't require system-level permission when patching protected default system roles

Mattermost doesn't require system-level permission when patching protected default system roles

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.26%via OSV
CVE-2026-6689Medium· 4.3
3mo ago

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.15%via OSV
CVE-2026-7184Medium· 6.5
3mo ago

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

Sunlitmattermost · github.com/mattermost/mattermost-serverEPSS 0.26%via OSV
CVE-2026-6961High· 7.6
3mo ago

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

Twilightmattermost · github.com/mattermost/mattermost-serverEPSS 0.30%via OSV
mattermost vulnerabilities (CVEs) · VulnSea