These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-10819 is a denial of service vulnerability affecting Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, and 11.7.x <= 11.7.4. The vulnerability allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji due to insufficient limits on the number of frames and file size. This issue can have a significant impact on the [truncated]
CVE-2026-10600 is a medium-severity vulnerability in Mattermost that allows an authenticated user with file-upload permission to degrade file uploads for all users on the server. The vulnerability is caused by a failure to bound the time and resource consumption of server-side document content extraction. This can lead to a denial-of-service (DoS) condition, where an attacker can repeatedly upload small d [truncated]
CVE-2026-9602 is a medium-severity vulnerability in Mattermost Desktop App versions <=6.2, 6.0.2, 5.6.13.0. The vulnerability allows a malicious server owner to crash the Mattermost Desktop App by changing the payload of a method to a malformed one. This issue arises from the app's failure to validate payloads sent from the Mattermost Web App to the Desktop App. Users of affected versions should be aware [truncated]
The CVE record for CVE-2026-8075 was published on 2026-07-17T11:17:15.180Z and has not been modified since then. The NVD entry is currently Received. This vulnerability affects Mattermost Desktop App versions <=6.2, 5.5.13, and 6.0.2.0, allowing a user to crash another channel member's Desktop App via a malicious link with an embedded image missing headers. The vulnerability has a CVSS score of 6.5, indic [truncated]
CVE-2026-9820 is a low-severity vulnerability affecting Mattermost versions 11.7.x <= 11.7.2 and 10.11.x <= 10.11.19. The issue arises from the failure to sanitize team objects returned by the scheme teams endpoint, enabling users with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint. The vulnerability has [truncated]
CVE-2026-6541 is a vulnerability in Mattermost that allows an authenticated user with team access to alter another user's playbook metric settings via a crafted import or update request with a foreign metric ID. Affected versions include 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, and 10.11.x <= 10.11.19. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. There is no evidence of exploitation in t [truncated]
CVE-2026-9708 is a medium-severity vulnerability affecting Mattermost, a popular communication platform used by numerous organizations for team collaboration and communication. The issue arises from inadequate access control validation for incoming webhooks, allowing users with webhook management permissions to create posts or direct messages attributed to another user via crafted configurations and paylo [truncated]
CVE-2026-9597 is a vulnerability in Mattermost versions 11.7.x <= 11.7.2 and 11.6.x <= 11.6.4. The issue allows deactivated guest users to obtain a fully functional session via a magic-link token issued prior to deactivation. This happens because the system fails to verify whether a guest account is deactivated before creating a session in the magic-link token login path. The vulnerability has a CVSS scor [truncated]
CVE-2026-9571: Mattermost OAuth Refresh Token Invalidation. Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation. This allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint. The vulnerability has a CVSS sco [truncated]
CVE-2026-6850 is a denial of service vulnerability in Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19. An authenticated attacker can cause a denial of service for all users in a channel via a post containing a specially crafted payload that triggers catastrophic backtracking in the client-side markdown parser. This issue affects users of Mattermost who have not applied patches. [truncated]
CVE-2026-10106 is a vulnerability in Mattermost that allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel. The vulnerability occurs because Mattermost fails to verify that the channel referenced in an action cookie matches the channel of the target post. This allows an authenticated user without access to a private channel to trigger [truncated]
CVE-2026-10103 is a medium-severity vulnerability affecting Mattermost, a popular communication platform. The issue arises from a failure to verify post ownership in the shared channel inbound sync handler. This weakness allows an authenticated remote cluster to modify or delete posts authored by local users or other remotes via crafted sync messages referencing arbitrary post IDs in channels shared with that remote.
CVE-2026-10085 is a vulnerability in Mattermost that allows an ordinary group or direct message member to remove all participants from a conversation via the channel patch API. The vulnerability is caused by a failure to restrict the group_constrained channel flag to public and private channels that support group synchronization. This issue can have significant operational impacts on organizations using a [truncated]
CVE-2026-4339 is a medium-severity vulnerability affecting Mattermost Server versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, and 11.5.x <= 11.5.6. The vulnerability is caused by a failure to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server. This allows an attacker with access to the MCP server in stdio mode to perform server-side request forgery (SS [truncated]
CVE-2026-3472 is a low-severity vulnerability in Mattermost Server versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, and 11.5.x <= 11.5.6. The vulnerability occurs because the application fails to properly apply markdown image rendering restrictions to AI bot tool result posts. This allows an authenticated attacker to inject markdown image syntax into tool result content rendered by a victim's client, poten [truncated]
The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google account to share Google Drive files to unauthorized private channels and disclose private channel membership. This vulnerability has a CVSS score of 4.2 and a severity of MEDIUM. The vulnerability is caused by a lack of validation [truncated]
CVE-2026-9162 is a medium-severity vulnerability affecting Mattermost Server versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, and 10.11.x <= 10.11.17. The issue arises from the failure to invalidate cached authentication state for active WebSocket connections during global session revocation. This allows a user with an existing WebSocket connection to remain authenticated and continue receiv [truncated]
CVE-2026-8683 is a medium-severity vulnerability in Mattermost Desktop App versions <=6.1 5.5.13.0. The vulnerability occurs when the application attempts to open extremely long URLs, which can be exploited by a malicious server owner to crash the application. This is achieved by including a script that calls window.open on a very large URL. The vulnerability has a CVSS score of 6.5 and is classified as CWE-770.
CVE-2026-6517 is a medium-severity vulnerability in the Mattermost Desktop App. Versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were forwarded. This allows any user on a server without the image proxy enabled to intercept other users' credentials via embedding an image that routes to an external web server. The vulnerability has a CVSS score of 6.3 and was publ [truncated]
CVE-2026-7387 is a high-severity vulnerability in Mattermost that allows for authorization bypass. The vulnerability affects Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, and 10.11.x <= 10.11.16. An attacker with group-link permissions can escalate themselves and group members to team or channel admin via crafted API requests. The vulnerability has a CVSS score of 8.8 and is [truncated]
CVE-2026-7184 is a medium-severity vulnerability in Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, and 10.11.x <= 10.11.15. The issue allows an attacker with the manage_secure_connections permission to obtain remote cluster authentication tokens via a PATCH request to the remote cluster endpoint due to a failure to sanitize the Remote Cluster API response on PATCH operations.
CVE-2026-6961 is a HIGH severity vulnerability with a CVSS score of 7.6. Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, and 10.11.x <= 10.11.16 are affected. The vulnerability is caused by Mattermost's failure to sanitize FileInfo.Name received from federated peers during shared channel file sync. This allows an attacker controlling a federated server to write files to arbitr [truncated]
CVE-2026-6739 is a medium-severity vulnerability in Mattermost that affects versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, and 10.11.x <= 10.11.16. The vulnerability allows authenticated users with delegated user-management permissions to escalate privileges by altering built-in role permissions via the role patch API. This is due to the failure of the system to require system-level per [truncated]
CVE-2026-6689 is a medium-severity vulnerability affecting Mattermost, a popular communication platform. The vulnerability has a CVSS score of 4.3 and was published on 2026-06-12. It allows an authenticated user with PermissionCreateTeam but not PermissionInviteUser on the resulting team to configure invite-controlled team settings, making the team publicly joinable or constraining membership via allowed domains.
CVE-2026-6046 is a medium-severity vulnerability in Mattermost, a popular communication platform. The issue arises from the platform's failure to validate that a username returned during bot registration belongs to a bot account. This oversight allows an unprivileged attacker to intercept private messages sent by plugins via direct message channels by pre-registering a user account with a predictable plug [truncated]
CVE-2026-3433 is a vulnerability in Mattermost, a self-hosted, open-source, and customizable platform for team communication. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. It was published on 2026-06-12T17:16:22.467Z and has not been modified since its publication.
A path traversal vulnerability in Mattermost Plugins versions 1.1.5 and earlier allows remote administrators of federated Mattermost servers to write files to arbitrary locations within a target server's filestore. The vulnerability exists because filenames received from federated peers are not sanitized before being used to construct export destination paths during shared-channel attachment synchronizati [truncated]
## Summary Mattermost versions 11.6.x through 11.6.0, 11.5.x through 11.5.3, 11.4.x through 11.4.4, and 10.11.x through 10.11.14 contain a denial-of-service vulnerability in outgoing webhook processing. An authenticated attacker can trigger server process termination by sending a crafted webhook callback response containing a null attachment entry. The root cause is improper filtering of nil elements in w [truncated]
CVE-2026-28735 is a medium-severity vulnerability affecting Mattermost Server versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, and 10.11.x <= 10.11.14. The issue arises from the failure to validate the OAuth token scope on the callback, which allows an authenticated Mattermost user to gain access to private repositories by modifying the scope parameter in the GitHub authorization URL. This v [truncated]
CVE-2026-5755 is a denial of service vulnerability in Mattermost Server versions 10.11.x through 11.6.x. Authenticated users with file upload or posting permissions can cause a server OOM by uploading a crafted TIFF file or posting a URL that serves one. This vulnerability occurs due to insufficient validation of TIFF IFD offsets in image headers before memory allocation. Users of affected versions should [truncated]
CVE-2026-5740 is a high-severity vulnerability affecting Mattermost Server versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, and 10.11.x <= 10.11.14. The vulnerability allows an unauthenticated remote attacker to crash the server process by sending a crafted binary WebSocket message to the public WebSocket endpoint, resulting in a full service outage for all users. The vulnerability is caused [truncated]
CVE-2026-5308 is a denial of service vulnerability in Mattermost Server versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14. The vulnerability occurs because the affected versions fail to enforce request body size limits on plugin HTTP endpoints, allowing an attacker to cause a denial of service via crafted oversized HTTP requests. This vulnerability has a CVSS score of 4.9, [truncated]
CVE-2026-4646 is a medium-severity vulnerability affecting Mattermost Server versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, and 10.11.x <= 10.11.14. The vulnerability allows an authenticated attacker to crash the plugin process via a crafted HTTP request to the PR details endpoint. The Mattermost Advisory ID for this vulnerability is MMSA-2026-00638. This issue has a CVSS score of 4.3 and [truncated]
CVE-2026-4635 is a medium-severity vulnerability affecting Mattermost Server versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, and 10.11.x <= 10.11.14. The issue arises from the failure to archive channels before removing persistent notifications, allowing an authenticated user to crash the server by timing the creation of persistent notification messages between server deletion of existing n [truncated]
CVE-2026-3636 is a medium-severity vulnerability in Mattermost Server, affecting versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, and 10.11.x <= 10.11.14. The issue allows users without elevated permissions to obtain data about team members' roles by invoking various team API endpoints. This vulnerability has been analyzed and addressed by the vendor. The affected product is Mattermost Serve [truncated]
CVE-2026-4858 is a Mattermost path traversal issue in integration action URL handling. According to the published description, a malicious authenticated user can bypass URL checks and use path traversal to call arbitrary APIs with the system admin Mattermost auth token. The issue is tracked by Mattermost as advisory MMSA-2026-00640 and is rated CVSS 8.0 (HIGH).
CVE-2026-22880 describes an SSO callback origin validation weakness in Mattermost Mobile Apps. According to the NVD entry and Mattermost reference, a malicious Mattermost server can abuse the mobile app’s SSO flow to relay the authentication exchange and capture credentials or tokens intended for a legitimate server. The issue is publicly disclosed with CWE-352 context and a CVSS 3.1 score of 6.1 (medium).
CVE-2026-4055 is a team-scoped authorization flaw in Mattermost playbook run creation. According to the NVD summary, versions 11.5.x through 11.5.1 fail to validate the target team’s run_create permission when a playbook run is created, which can let an authenticated team member create runs in a team where they do not have permission by specifying a different team ID in the API request. The issue is rated [truncated]
CVE-2026-6347 is a high-severity information disclosure issue in the Mattermost Calls plugin. In affected Mattermost releases, sensitive configuration fields are not properly sanitized when a support packet is generated, which can leave TURN server credentials in plaintext inside the exported plugin configuration. Anyone with access to that support packet could recover the credentials. The CVE was publish [truncated]
Mattermost fixed a credential-exposure issue in support packet generation that affected specific 10.11.x, 11.4.x, and 11.5.x releases. On vulnerable versions, sensitive configuration fields were not sanitized before a support packet was created, so a System Admin or anyone with access to the packet could retrieve plaintext credentials from the downloaded file. NVD rates the issue as high severity (CVSS 8. [truncated]
CVE-2026-6345 describes a Mattermost Server issue where created user passwords were not adequately protected from disclosure. According to the vendor and NVD, a malicious attacker with sufficient privileges could use exposed passwords to impersonate a user. The issue is rated medium severity with high confidentiality and integrity impact.
CVE-2026-6343 is a Mattermost authorization issue published on 2026-05-18. According to the vendor/NVD record, certain Mattermost Server versions fail to correctly enforce public/private permissions, which can allow users without those permissions to access public playbooks through the /get endpoint. NVD rates the issue CVSS 3.1 4.3 (Medium), with low-privilege, network-reachable access and a confidential [truncated]
CVE-2026-6339 is a Mattermost vulnerability published on 2026-05-18 that can let an authenticated channel member force the reveal of a burn-on-read message without recipient consent. The issue affects Mattermost Server 11.4.0 through 11.4.3 and 11.5.0 through 11.5.1, with vendor and NVD records identifying it as a low-severity, network-reachable issue with limited availability impact.
CVE-2026-4286 is a low-severity Mattermost authorization issue affecting playbook updates. According to the vendor and NVD data, users with only Manage Playbook Configurations permission could change a playbook’s team through the update API because the application did not verify whether {{team_id}} was being changed. That bypassed the intended manage members restriction for team changes. The affected rang [truncated]
CVE-2026-3471 is a medium-severity denial-of-service issue in the Mattermost Desktop App. According to the CVE description, the app fails to block an invalid URL from loading inside a pop-up window, which can let a malicious server owner repeatedly crash the application by invoking window.open('javascript:alert()');. The issue was publicly disclosed on 2026-05-18 and is associated with Mattermost advisory [truncated]
A missing authorization check in the Mattermost GitLab plugin allows authenticated users to perform administrative actions. The vulnerability exists in the plugin's command handlers for `gitlab instance` and `/gitlab webhook` commands, which fail to verify that the invoking user has appropriate permissions before executing instance uninstallation or webhook configuration operations. This represents a clas [truncated]
CVE-2026-6342 is a low-complexity authorization flaw in Mattermost Plugins that can let a plugin user create subscriptions to groups they were not supposed to access. The issue stems from insufficient validation of namespaces: if a user can create a group whose name shares a prefix with a whitelisted group, the plugin may treat it as valid. Mattermost’s advisory and the NVD record both tie this to a permi [truncated]
A missing authorization check in Mattermost Plugins allows authenticated users with membership in multiple groups to bypass group-level restrictions when creating issues or attaching comments via direct API requests. The vulnerability stems from insufficient API-level validation of group permissions, enabling users to interact with locked groups they should not access. This affects Mattermost Plugins vers [truncated]
CVE-2026-6340 is a denial-of-service issue in Mattermost’s handling of 7zip archives. According to the provided description, affected versions fail to validate 7zip archive structure before processing, allowing an authenticated attacker to upload a specially crafted archive with excessive folder declarations and trigger server memory exhaustion. The result is loss of availability rather than direct data e [truncated]
CVE-2026-6334 is a low-severity OAuth authorization flaw reported for Mattermost. According to the CVE description and NVD record, affected versions fail to enforce client identity binding during authorization code redemption, which can allow one authenticated OAuth client to redeem an authorization code issued to a different client. The issue was published on 2026-05-18 and the only cited vendor referenc [truncated]