Vulnerabilidades en Mattermost

438 resultados
Análisis Vexday

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2025-3230MEDIUMBypass of System Admin User Deactivation Controls for Personal Access Tokens in Mattermost ServerEPSS 0.2%CVE-2025-2475MEDIUMUnauthorized Bot Login Using CredentialsEPSS 0.2%CVE-2025-12559MEDIUMInformation Disclosure in Common Teams APIEPSS 0.2%CVE-2026-6517MEDIUMMattermost Desktop App fails to restrict the allow list of domains which NTLM credentials are passedEPSS 0.2%CVE-2025-13870LOWUnauthorized access and subscription vulnerability in BoardsEPSS 0.2%CVE-2023-5920LOWLack Of Secure Keyboard Entry Protection in MacOS DesktopEPSS 0.2%CVE-2025-49810LOWThread summarization allows persistent access to channelEPSS 0.2%CVE-2025-8285MEDIUMUnauthorized Channel Subscription Creation in Mattermost Confluence PluginEPSS 0.2%CVE-2026-3471MEDIUMOpening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop AppEPSS 0.2%CVE-2026-3636MEDIUMSanitize team member data returned by APIEPSS 0.2%CVE-2026-21386MEDIUMPrivate channel enumeration via /mute slash commandEPSS 0.2%CVE-2025-53910MEDIUMUnauthorized Channel Subscription Edit in Mattermost Confluence PluginEPSS 0.2%CVE-2024-36255MEDIUMPost actions can run playbook checklist task commandsEPSS 0.2%CVE-2025-4128LOWMattermost Guest User Information Disclosure VulnerabilityEPSS 0.2%CVE-2025-24839LOWUnauthorized AI bot activation via Wrangler pluginEPSS 0.2%CVE-2026-27656MEDIUMAccount Takeover via Substring Matching in OpenID Connect AuthenticationEPSS 0.2%CVE-2026-3433MEDIUMMattermost fails to scope role_updated websocket events to authorized team and channel membersEPSS 0.2%CVE-2026-2476HIGHMS Teams plugin sensitive config values not properly masked in support packetsEPSS 0.2%CVE-2025-46702MEDIUMMattermost Playbooks allows privilege escalation through improper access control in playbook run participant managementEPSS 0.2%CVE-2026-6673MEDIUMMattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud installEPSS 0.2%