VendorsMattermostmattermost_serverall versions
Vulnerabilities

Mattermost Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

467CVEs
CVE-2024-5272
Run Details leak to guest via webhook event "custom_playbooks_playbook_run_updated"
Published 2024-05-26 · Analyzed
4.3EPSS 0.003
CVE-2025-2564
Unauthorized View Access to Archived Channel Member Info
Published 2025-04-16 · Analyzed
4.3EPSS 0.003
CVE-2024-43780
Unauthorized channel file upload
Published 2024-08-22 · Analyzed
4.3EPSS 0.003
CVE-2024-50052
Arbitrary post deletion via Playbooks /ignore-thread endpoint
Published 2024-10-29 · Analyzed
4.3EPSS 0.003
CVE-2024-41162
Malicious remote can make an arbitrary local channel read-only
Published 2024-08-01 · Analyzed
4.3EPSS 0.003
CVE-2024-5270
SAML to email switch possible when email signin is disabled
Published 2024-05-26 · Analyzed
4.3EPSS 0.003
CVE-2025-41423
Unauthorized Playbooks Post Deletion in Mattermost Playbooks Plugin
Published 2025-04-24 · Analyzed
4.3EPSS 0.003
CVE-2026-16047
Board channel linking without read channel permission validation
Published 2026-08-17 · Analyzed
4.3EPSS 0.003
CVE-2026-3115
Guest users can view group member IDs without respecting view restrictions
Published 2026-03-26 · Analyzed
4.3EPSS 0.003
CVE-2026-9824
Remote cluster metadata enumeration via /share-channel autocomplete
Published 2026-07-13 · Analyzed
4.3EPSS 0.003
CVE-2026-6343
Mattermost Playbooks Plugin fails to enforce view permissions in list endpoints, allowing unauthorized access to public playbooks
Published 2026-05-18 · Analyzed
4.3EPSS 0.003
CVE-2026-4053
post edit time limit is not enforced on some post update operations
Published 2026-05-15 · Analyzed
4.3EPSS 0.003
CVE-2025-27571
Channel metadata visible in archived channels despite configuration setting
Published 2025-04-16 · Analyzed
4.3EPSS 0.003
CVE-2024-9155
Insufficient Authorization On Unlinked Channel Files
Published 2024-09-26 · Analyzed
4.3EPSS 0.003
CVE-2024-34152
Playbook Run Metadata leak to Guest
Published 2024-05-26 · Analyzed
4.3EPSS 0.003
CVE-2024-36241
/playbook add slash command allows viewing arbitrary post contents
Published 2024-05-26 · Analyzed
4.3EPSS 0.003
CVE-2026-4055
Insufficient permission validation on cross-team playbook run creation
Published 2026-05-21 · Analyzed
4.3EPSS 0.003
CVE-2026-6342
Group prefix matching bypass for subscriptions
Published 2026-05-18 · Analyzed
4.3EPSS 0.003
CVE-2026-16046
Missing run-state validation on finished playbook runs
Published 2026-08-17 · Analyzed
4.3EPSS 0.003
CVE-2026-3637
Mattermost fails to enforce create_post permission when editing posts
Published 2026-05-18 · Analyzed
4.3EPSS 0.003
CVE-2026-26304
Permission Bypass in Playbook Run Creation
Published 2026-03-16 · Analyzed
4.3EPSS 0.003
CVE-2026-28732
Slash command trigger-word update allowed command hijacking
Published 2026-05-18 · Analyzed
4.3EPSS 0.003
CVE-2026-28759
Insufficient authorization in shared channel membership sync allows remote cluster to remove users from arbitrary channels
Published 2026-05-18 · Analyzed
4.3EPSS 0.003
CVE-2026-6689
*Missing* {{invite_user}} *permission check on team creation allows unprivileged users to set open-invite and allowed-domains team settings*
Published 2026-06-12 · Analyzed
4.3EPSS 0.003
CVE-2026-6541
Unscoped updates to other playbooks' metric configuration
Published 2026-07-13 · Analyzed
4.3EPSS 0.003
CVE-2026-6341
Incomplete group locking implementation
Published 2026-05-18 · Analyzed
4.3EPSS 0.003
CVE-2025-2424
Leaked Metadata of Deleted Files via Bookmark Creation
Published 2025-04-14 · Analyzed
4.3EPSS 0.003
CVE-2024-47145
Unauthorized access on archived channels via file links
Published 2024-09-26 · Analyzed
4.3EPSS 0.003
CVE-2026-22892
Insufficient Authorization in Mattermost Jira Plugin Allows Unauthorized Access to Post Attachments
Published 2026-02-13 · Analyzed
4.3EPSS 0.002
CVE-2025-1472
Unauthorized View Access to Site Statistics and Team Statistics
Published 2025-03-19 · Analyzed
4.3EPSS 0.002
CVE-2025-3227
Unauthorized channel member management through playbook runs
Published 2025-06-20 · Analyzed
4.3EPSS 0.002
CVE-2025-3446
Members Without Guest Invite Permissions Can Add Guests to Teams
Published 2025-05-15 · Analyzed
4.3EPSS 0.002
CVE-2024-29215
Slash commands run in channel without channel membership via playbook task commands
Published 2024-05-26 · Analyzed
4.3EPSS 0.002
CVE-2026-10103
Authenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared channels
Published 2026-07-13 · Analyzed
4.3EPSS 0.002
CVE-2026-4273
Insufficient token rotation validation in remote cluster invite confirmation
Published 2026-05-18 · Analyzed
4.3EPSS 0.002
CVE-2026-4286
Playbooks Plugin fails to validate team transfers, allowing unauthorized removal of member access via playbook update
Published 2026-05-18 · Analyzed
4.3EPSS 0.002
CVE-2025-24920
Unauthorized Bookmark Creation and Modification in Archived Channels
Published 2025-03-21 · Analyzed
4.3EPSS 0.002
CVE-2025-3611
Improper Access Control in Mattermost allows System Managers to view team details despite role restrictions
Published 2025-05-30 · Analyzed
4.3EPSS 0.002
CVE-2025-13870
Unauthorized access and subscription vulnerability in Boards
Published 2025-12-02 · Analyzed
4.3EPSS 0.002
CVE-2025-24839
Unauthorized AI bot activation via Wrangler plugin
Published 2025-04-16 · Analyzed
4.3EPSS 0.002
← Prev10 / 12Next →