mattermost
Latest CVEs
The 15 most recently published vulnerabilities affecting mattermost.
- CVE-2026-75587Plaintext pre-auth secret exposure via Desktop App diagnostics report3.6
- CVE-2026-9693Mattermost thread memberships persist after team removal, exposing private channel thread metadata on re-invite3.5
- CVE-2026-9859Mattermost Boards plugin didn’t enforce role-based authorization on board channel link allowing board editors to expose boards to arbitrary channels6.5
- CVE-2026-9816Insufficient server-side validation of board member role fields permits privilege escalation8.3
- CVE-2026-10080Boards plugin panics on WebSocket command with non-string field types6.5
- CVE-2026-10527Boards plugin retains Board Admin rights for users demoted to System Guest6.3
- CVE-2026-15754Missing per-channel team-scope check in ABAC access control policy unassign allows cross-team policy removal4.2
- CVE-2026-16044Insufficient validation of guest board admin privileges on archive import5.4
- CVE-2026-16045Delegated OAuth tokens could revoke unrelated OAuth application authorizations4.3
- CVE-2026-16049_GitLab Plugin allows cross-channel post injection and phishing via missing channel permission checks in issue API endpoints_4.3
- CVE-2026-16047Board channel linking without read channel permission validation4.3
- CVE-2026-16046Missing run-state validation on finished playbook runs4.3
- CVE-2026-16048Channel member roles accept out-of-scope roles6.3
- CVE-2026-14298Denial of service via resource exhaustion in Mattermost6.5
- CVE-2026-7521SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory5.5