Vulnerabilities in Mattermost

489 results
Vexday analysis

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2025-3446MEDIUMMembers Without Guest Invite Permissions Can Add Guests to TeamsEPSS 0.2%CVE-2025-32093MEDIUMSyatem admin profile modification by delegated granular administration roleEPSS 0.2%CVE-2024-31859MEDIUMMember promoted to channel admin via playbooks run linking to channelEPSS 0.2%CVE-2026-4054MEDIUMSVG content served through Mattermost image proxy despite Content-Type restrictions causes client-side denial of serviceEPSS 0.2%CVE-2026-10103MEDIUMAuthenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared channelsEPSS 0.2%CVE-2025-1792LOWImproper Access Control in Mattermost Channel Member APIEPSS 0.2%CVE-2026-6062MEDIUMIDOR in Jira plugin subscription edit endpointEPSS 0.2%CVE-2026-14298MEDIUMBoards archive import endpoint allows resource exhaustion via zip bomb and file size limit bypass in MattermostEPSS 0.2%CVE-2026-6340MEDIUMMemory Exhaustion via Malicious 7zip File UploadEPSS 0.2%CVE-2025-27538LOWMFA Enforcement Bypass Allows Unauthorized Removal of MFA for Other UsersEPSS 0.2%CVE-2026-2325MEDIUMImproper Input Validation in MS Teams Meetings API HandlerEPSS 0.2%CVE-2026-10819MEDIUMMattermost Server Denial of Service via Animated GIF Emoji UploadEPSS 0.2%CVE-2025-54478HIGHUnauthenticated Channel Subscription Edit in Mattermost Confluence PluginEPSS 0.2%CVE-2024-32945LOWLaTeX post content manipulation via renderer state leak across contextsEPSS 0.2%CVE-2026-15814MEDIUMUploading a crafted image causes excessive memory allocation in the Mattermost ServerEPSS 0.2%CVE-2026-5132MEDIUMUnbounded zlib decompression in Calls SDP WebSocket messagesEPSS 0.2%CVE-2025-24920MEDIUMUnauthorized Bookmark Creation and Modification in Archived ChannelsEPSS 0.2%CVE-2026-6345MEDIUMPrevent password disclosure and force reset during Slack importEPSS 0.2%CVE-2026-3115MEDIUMGuest users can view group member IDs without respecting view restrictionsEPSS 0.2%CVE-2026-9597MEDIUMDeactivated guest accounts can authenticate via magic-link token in Mattermost REST API login endpointEPSS 0.2%