PatchSiren cyber security CVE debrief
CVE-2026-3495 Mattermost CVE debrief
Mattermost Server versions 11.5.x through 11.5.1 and 10.11.x through 10.11.13 contain a stored cross-site scripting (XSS) vulnerability in error page composition. The application fails to properly escape variables that may contain malicious content when rendering error pages. An attacker with administrative privileges to edit site configuration can inject JavaScript payloads into these variables, which execute when error pages are rendered. The vulnerability requires high privileges (administrative access to site configuration), limiting its exploitability. The CVSS 3.1 score of 3.8 reflects this high privilege requirement and network-based attack vector with low confidentiality and integrity impact. Mattermost has assigned advisory ID MMSA-2026-00622 to this issue.
- Vendor
- Mattermost
- Product
- Unknown
- CVSS
- LOW 3.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-18
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-18
- Advisory updated
- 2026-05-19
Who should care
Mattermost Server administrators and security teams responsible for collaboration platform security. Organizations running affected versions with multiple administrators or delegated configuration management roles face elevated risk of insider abuse. Security-conscious deployments with strict administrative access controls have reduced exposure.
Technical summary
The vulnerability exists in error page template rendering where dynamic variables are not properly HTML-escaped before output. An attacker with site configuration editing privileges can manipulate configuration values that populate error page templates, embedding JavaScript payloads. When error conditions trigger these pages, the unescaped content renders in the victim's browser context. The attack requires authenticated administrative access, making it a privileged insider threat scenario rather than unauthenticated exploitation.
Defensive priority
routine
Recommended defensive actions
- Upgrade Mattermost Server to version 10.11.14 or later for 10.11.x branch, or version 11.5.2 or later for 11.5.x branch
- Review site configuration settings for unauthorized modifications, particularly any injected scripts in error-related variables
- Implement principle of least privilege for administrative accounts with site configuration access
- Monitor error page rendering for unexpected script execution
- Apply security updates from Mattermost security advisories promptly
Evidence notes
Vulnerability confirmed through NVD analysis with vendor advisory from Mattermost. CWE-79 (Improper Neutralization of Input During Web Page Generation) identified as the underlying weakness. Affected versions explicitly defined in CPE criteria: 10.11.0 to 10.11.13 and 11.5.0 to 11.5.1.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-3495 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-3495
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-3495 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3495
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://mattermost.com/security-updates
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.