These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The Mattermost Desktop App vulnerability allows a network-positioned attacker to load a plugin popout window over an insecure connection via a link using a downgraded URL scheme. This issue affects versions <=6.2 6.2.2.0 and has been assigned a CVSS score of 2.6. The CVE record was published on 2026-09-17T16:17:41.940Z and was last modified on 2026-09-18T13:46:33.503Z.
The Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler, allowing a malicious or compromised Mattermost server to disconnect an active call belonging to a different connected server. This vulnerability could disrupt communication and impact the availability of the application. Defenders should assess exposure and prioritize patching for affected versions [truncated]
CVE-2026-14298 is a vulnerability in Mattermost's Boards archive import handler that allows an authenticated user to cause memory exhaustion or unbounded disk consumption via a crafted .boardarchive file. The vulnerability affects Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, and 10.11.x <= 10.11.22. This issue arises from the failure to limit decompressed content size and enfo [truncated]
CVE-2026-10819 is a denial of service vulnerability affecting Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, and 11.7.x <= 11.7.4. The vulnerability allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji due to insufficient limits on the number of frames and file size. This issue can have a significant impact on the [truncated]
CVE-2026-10600 is a medium-severity vulnerability in Mattermost that allows an authenticated user with file-upload permission to degrade file uploads for all users on the server. The vulnerability is caused by a failure to bound the time and resource consumption of server-side document content extraction. This can lead to a denial-of-service (DoS) condition, where an attacker can repeatedly upload small d [truncated]
CVE-2026-9602 is a medium-severity vulnerability in Mattermost Desktop App versions <=6.2, 6.0.2, 5.6.13.0. The vulnerability allows a malicious server owner to crash the Mattermost Desktop App by changing the payload of a method to a malformed one. This issue arises from the app's failure to validate payloads sent from the Mattermost Web App to the Desktop App. Users of affected versions should be aware [truncated]
The CVE record for CVE-2026-8075 was published on 2026-07-17T11:17:15.180Z and has not been modified since then. The NVD entry is currently Received. This vulnerability affects Mattermost Desktop App versions <=6.2, 5.5.13, and 6.0.2.0, allowing a user to crash another channel member's Desktop App via a malicious link with an embedded image missing headers. The vulnerability has a CVSS score of 6.5, indic [truncated]
CVE-2026-9820 is a low-severity vulnerability affecting Mattermost versions 11.7.x <= 11.7.2 and 10.11.x <= 10.11.19. The issue arises from the failure to sanitize team objects returned by the scheme teams endpoint, enabling users with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint. The vulnerability has [truncated]
CVE-2026-6541 is a vulnerability in Mattermost that allows an authenticated user with team access to alter another user's playbook metric settings via a crafted import or update request with a foreign metric ID. Affected versions include 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, and 10.11.x <= 10.11.19. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. There is no evidence of exploitation in t [truncated]
CVE-2026-9708 is a medium-severity vulnerability affecting Mattermost, a popular communication platform used by numerous organizations for team collaboration and communication. The issue arises from inadequate access control validation for incoming webhooks, allowing users with webhook management permissions to create posts or direct messages attributed to another user via crafted configurations and paylo [truncated]
CVE-2026-9597 is a vulnerability in Mattermost versions 11.7.x <= 11.7.2 and 11.6.x <= 11.6.4. The issue allows deactivated guest users to obtain a fully functional session via a magic-link token issued prior to deactivation. This happens because the system fails to verify whether a guest account is deactivated before creating a session in the magic-link token login path. The vulnerability has a CVSS scor [truncated]
CVE-2026-9571: Mattermost OAuth Refresh Token Invalidation. Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation. This allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint. The vulnerability has a CVSS sco [truncated]
CVE-2026-6850 is a denial of service vulnerability in Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19. An authenticated attacker can cause a denial of service for all users in a channel via a post containing a specially crafted payload that triggers catastrophic backtracking in the client-side markdown parser. This issue affects users of Mattermost who have not applied patches. [truncated]
CVE-2026-10106 is a vulnerability in Mattermost that allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel. The vulnerability occurs because Mattermost fails to verify that the channel referenced in an action cookie matches the channel of the target post. This allows an authenticated user without access to a private channel to trigger [truncated]
CVE-2026-10103 is a medium-severity vulnerability affecting Mattermost, a popular communication platform. The issue arises from a failure to verify post ownership in the shared channel inbound sync handler. This weakness allows an authenticated remote cluster to modify or delete posts authored by local users or other remotes via crafted sync messages referencing arbitrary post IDs in channels shared with that remote.
CVE-2026-10085 is a vulnerability in Mattermost that allows an ordinary group or direct message member to remove all participants from a conversation via the channel patch API. The vulnerability is caused by a failure to restrict the group_constrained channel flag to public and private channels that support group synchronization. This issue can have significant operational impacts on organizations using a [truncated]
CVE-2026-4339 is a medium-severity vulnerability affecting Mattermost Server versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, and 11.5.x <= 11.5.6. The vulnerability is caused by a failure to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server. This allows an attacker with access to the MCP server in stdio mode to perform server-side request forgery (SS [truncated]
CVE-2026-3472 is a low-severity vulnerability in Mattermost Server versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, and 11.5.x <= 11.5.6. The vulnerability occurs because the application fails to properly apply markdown image rendering restrictions to AI bot tool result posts. This allows an authenticated attacker to inject markdown image syntax into tool result content rendered by a victim's client, poten [truncated]
The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership. This vulnerability has a CVSS score of 4.2 and a severity of MEDIUM. The vulnerability is caused by a lack of validation [truncated]
CVE-2026-9162 is a medium-severity vulnerability affecting Mattermost Server versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, and 10.11.x <= 10.11.17. The issue arises from the failure to invalidate cached authentication state for active WebSocket connections during global session revocation. This allows a user with an existing WebSocket connection to remain authenticated and continue receiv [truncated]
CVE-2026-8683 is a medium-severity vulnerability in Mattermost Desktop App versions <=6.1 5.5.13.0. The vulnerability occurs when the application attempts to open extremely long URLs, which can be exploited by a malicious server owner to crash the application. This is achieved by including a script that calls window.open on a very large URL. The vulnerability has a CVSS score of 6.5 and is classified as CWE-770.
CVE-2026-6517 is a medium-severity vulnerability in the Mattermost Desktop App. Versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded. This allows any user on a server without the image proxy enabled to intercept other users' credentials via embedding an image that routes to an external web server. The vulnerability has a CVSS score of 6.3 and was publ [truncated]
CVE-2026-7387 is a high-severity vulnerability in Mattermost that allows for authorization bypass. The vulnerability affects Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, and 10.11.x <= 10.11.16. An attacker with group-link permissions can escalate themselves and group members to team or channel admin via crafted API requests. The vulnerability has a CVSS score of 8.8 and is [truncated]
CVE-2026-7184 is a medium-severity vulnerability in Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, and 10.11.x <= 10.11.15. The issue allows an attacker with the manage_secure_connections permission to obtain remote cluster authentication tokens via a PATCH request to the remote cluster endpoint due to a failure to sanitize the Remote Cluster API response on PATCH operations.
CVE-2026-6961 is a HIGH severity vulnerability with a CVSS score of 7.6. Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, and 10.11.x <= 10.11.16 are affected. The vulnerability is caused by Mattermost's failure to sanitize FileInfo.Name received from federated peers during shared channel file sync. This allows an attacker controlling a federated server to write files to arbitr [truncated]
CVE-2026-6739 is a medium-severity vulnerability in Mattermost that affects versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, and 10.11.x <= 10.11.16. The vulnerability allows authenticated users with delegated user-management permissions to escalate privileges by altering built-in role permissions via the role patch API. This is due to the failure of the system to require system-level per [truncated]
CVE-2026-6689 is a medium-severity vulnerability affecting Mattermost, a popular communication platform. The vulnerability has a CVSS score of 4.3 and was published on 2026-06-12. It allows an authenticated user with PermissionCreateTeam but not PermissionInviteUser on the resulting team to configure invite-controlled team settings, making the team publicly joinable or constraining membership via allowed domains.
CVE-2026-6046 is a medium-severity vulnerability in Mattermost, a popular communication platform. The issue arises from the platform's failure to validate that a username returned during bot registration belongs to a bot account. This oversight allows an unprivileged attacker to intercept private messages sent by plugins via direct message channels by pre-registering a user account with a predictable plug [truncated]
CVE-2026-3433 is a vulnerability in Mattermost, a self-hosted, open-source, and customizable platform for team communication. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. It was published on 2026-06-12T17:16:22.467Z and has not been modified since its publication.
A path traversal vulnerability in Mattermost Plugins versions 1.1.5 and earlier allows remote administrators of federated Mattermost servers to write files to arbitrary locations within a target server's filestore. The vulnerability exists because filenames received from federated peers are not sanitized before being used to construct export destination paths during shared-channel attachment synchronizati [truncated]