mattermost has 64 CVEs on record between 2023 and 2026. Disclosure cadence is accelerating: 23 in the last 90 days against 15 in the 90 before. The busiest recent month was September 2026 with 22. The median CVSS is 5.2 (medium), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-862 (5) and CWE-863 (4). Most affected products: Mattermost (23), github.com/mattermost/mattermost/server/v8 (22), github.com/mattermost/mattermost-server (14).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.2
- Publish → KEV
- —
- Last 90 days
- 23 prev 15
Products
- Mattermost 23
- github.com/mattermost/mattermost/server/v8 22
- github.com/mattermost/mattermost-server 14
- github.com/mattermost/mattermost-server/v6 2
- github.com/mattermost/mattermost-plugin-playbooks 1
- legal_hold 1
Worst active — by depth score
CVE-2025-25279Critical· 9.9Mattermost allows reading arbitrary files related to importing boards71CVE-2026-7387High· 8.8Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints48CVE-2026-3524High· 8.8Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API …48CVE-2026-6961High· 7.6Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync42CVE-2026-8821High· 7.1Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrar…39
mattermost vulnerabilities
CVEs affecting mattermost, newest first. Open any entry for full detail, references, and exploit status.
64 CVEsRSS
CVE-2026-6739Medium· 6.7Mattermost doesn't require system-level permission when patching protected default system roles
Mattermost doesn't require system-level permission when patching protected default system roles
CVE-2026-6689Medium· 4.3Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
CVE-2026-7184Medium· 6.5Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
CVE-2026-6961High· 7.6Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
CVE-2026-7387High· 8.8Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
CVE-2026-6046Medium· 5.3Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
CVE-2026-22880Medium· 6.1Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credenti…
Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Mattermost server to steal user credenti…
CVE-2026-3524High· 8.8Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API …
Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API …
CVE-2025-1792Low· 3.1Mattermost fails to properly enforce access controls for guest users
Mattermost fails to properly enforce access controls for guest users
CVE-2025-3611Low· 3.1Mattermost fails to properly enforce access control restrictions for System Manager roles
Mattermost fails to properly enforce access control restrictions for System Manager roles
CVE-2025-35965Medium· 6.5Mattermost Playbooks fails to validate the uniqueness and quantity of task actions
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions
CVE-2025-41395Medium· 6.5Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
CVE-2025-27936Medium· 5.3Mattermost vulnerable to Observable Timing Discrepancy
Mattermost vulnerable to Observable Timing Discrepancy
CVE-2025-2475Medium· 5.4Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm
Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm
CVE-2025-32093Medium· 4.7Mattermost Fails to Restrict Certain Operations on System Admins
Mattermost Fails to Restrict Certain Operations on System Admins
CVE-2025-25279Critical· 9.9PoCMattermost allows reading arbitrary files related to importing boards
Mattermost allows reading arbitrary files related to importing boards
CVE-2025-20086Medium· 6.5Mattermost fails to properly validate post props
Mattermost fails to properly validate post props
CVE-2025-20088Medium· 6.5Mattermost fails to properly validate post props
Mattermost fails to properly validate post props
CVE-2025-22445Low· 3.5Mattermost has Improper Check for Unusual or Exceptional Conditions
Mattermost has Improper Check for Unusual or Exceptional Conditions
CVE-2025-20033Medium· 4.3Mattermost Improper Validation of Specified Type of Input vulnerability
Mattermost Improper Validation of Specified Type of Input vulnerability
CVE-2024-47401Medium· 4.3Mattermost Server vulnerable to application crash from attacker-generated large response
Mattermost Server vulnerable to application crash from attacker-generated large response
CVE-2024-46872Medium· 4.6Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
CVE-2024-10241Medium· 4.3Mattermost Server allows user to get private channel names
Mattermost Server allows user to get private channel names
CVE-2024-47003Medium· 5.4Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events
CVE-2024-1949Low· 2.6Mattermost race condition
Mattermost race condition
CVE-2024-1952Low· 3.1Mattermost incorrectly allows access individual posts
Mattermost incorrectly allows access individual posts
CVE-2024-23493Medium· 4.3Mattermost leaks details of AD/LDAP groups of a teams
Mattermost leaks details of AD/LDAP groups of a teams
CVE-2024-24988Medium· 4.3Mattermost denial of service through long emoji value
Mattermost denial of service through long emoji value
CVE-2024-1402Medium· 4.3Mattermost vulnerable to denial of service via large number of emoji reactions
Mattermost vulnerable to denial of service via large number of emoji reactions
CVE-2023-6458High· 7.1Mattermost Injection vulnerability
Mattermost Injection vulnerability