Vulnerabilities in Mattermost

489 results
Vexday analysis

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2026-21386MEDIUMPrivate channel enumeration via /mute slash commandEPSS 0.2%CVE-2026-3636MEDIUMSanitize team member data returned by APIEPSS 0.2%CVE-2025-6227LOWInvite token is used as part of the secure communicationEPSS 0.2%CVE-2024-36255MEDIUMPost actions can run playbook checklist task commandsEPSS 0.2%CVE-2025-55073MEDIUMMS Teams plugin OAuth allows editing arbitrary postsEPSS 0.2%CVE-2025-11777LOWCross-team channel membership accessEPSS 0.2%CVE-2025-12756MEDIUMInsecure Direct Object Reference in Mattermost Boards Plugin Enables Unauthorised Comment DeletionEPSS 0.2%CVE-2026-3433MEDIUMMattermost fails to scope role_updated websocket events to authorized team and channel membersEPSS 0.2%CVE-2026-27656MEDIUMAccount Takeover via Substring Matching in OpenID Connect AuthenticationEPSS 0.2%CVE-2026-2476HIGHMS Teams plugin sensitive config values not properly masked in support packetsEPSS 0.2%CVE-2026-0999MEDIUMAuthentication bypass via userID login when email and username login are disabledEPSS 0.2%CVE-2025-48731MEDIUMUnauthorized Subscription Edit to Confluence Space in Mattermost Confluence PluginEPSS 0.2%CVE-2024-41926LOWMalicious remote can claim that a user was synced from another remoteEPSS 0.2%CVE-2025-64641MEDIUMMattermost Jira plugin crafted action leaks Jira issue detailsEPSS 0.2%CVE-2025-13352LOWMattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijackingEPSS 0.2%CVE-2024-12247MEDIUMImproper propagation of permission scheme updates across cluster nodesEPSS 0.2%CVE-2025-9072HIGHOne-Click Mattermost Account Takeover via Poisoned RelayState SAML ParameterEPSS 0.2%CVE-2025-9084LOWOpen redirect in OAuth loginEPSS 0.2%CVE-2026-4635MEDIUMPersistent notification timing attack causing server denial of serviceEPSS 0.2%CVE-2026-4643LOWCalling window.close() from server-side content causes crash in the Mattermost Desktop AppEPSS 0.2%