Mattermost
This hub aggregates every CVE we track for Mattermost, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
429
CVEs tracked
7
Critical
33
High
0
In CISA KEV
Severity distribution
MEDIUM275LOW114HIGH33CRITICAL7
Monthly trend
9
5
4
5
12
6
9
14
9
7
3
9
6
8
11
12
2
9
34
6
36
18
15
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Mattermost.
- CVE-2026-7521SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory5.5
- CVE-2026-10819Mattermost Server Denial of Service via Animated GIF Emoji Upload6.5
- CVE-2026-10600Denial of service via unbounded document content extraction in Mattermost Server4.3
- CVE-2026-8075Posting a malicious markdown image crashes the Mattermost Desktop App6.5
- CVE-2026-9602Mattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methods6.5
- CVE-2026-6541Unscoped updates to other playbooks' metric configuration4.3
- CVE-2026-9820Mattermost schemes teams endpoint exposes private team invite IDs3.8
- CVE-2026-9824Remote cluster metadata enumeration via /share-channel autocomplete4.3
- CVE-2026-9597Deactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpoint5.4
- CVE-2026-6850Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost6.5
- CVE-2026-10106Unauthorized users can trigger interactive post actions in private channels via action cookie channel mismatch in Mattermost6.5
- CVE-2026-10085Ordinary group/direct message member can enable group_constrained and remove all channel participants5.4
- CVE-2026-9708Incoming webhook user attribution via unvalidated webhook owner4.9
- CVE-2026-10103Authenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared channels4.3
- CVE-2026-9571Deactivated user accounts can continue to obtain valid OAuth access tokens via refresh token grant in Mattermost5.9
Product normalization is registry-driven with AI assist and human review. How it works