Vulnerabilidades en Mattermost

489 resultados
Análisis Vexday

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2025-49221LOWUnauthenticated Access to Channel Subscription in Mattermost Confluence PluginEPSS 0.2%CVE-2026-22892MEDIUMInsufficient Authorization in Mattermost Jira Plugin Allows Unauthorized Access to Post AttachmentsEPSS 0.2%CVE-2026-10556MEDIUMUnauthenticated webhook request with null notification entry could crash the Microsoft Calendar plugin.EPSS 0.2%CVE-2026-3473MEDIUMImproper file ownership validation in the Boards API allows unauthorised file accessEPSS 0.2%CVE-2025-1472MEDIUMUnauthorized View Access to Site Statistics and Team StatisticsEPSS 0.2%CVE-2026-15754MEDIUMMissing per-channel team-scope check in ABAC access control policy unassign allows cross-team policy removalEPSS 0.2%CVE-2025-3227MEDIUMUnauthorized channel member management through playbook runsEPSS 0.2%CVE-2024-23319LOWCSRF issue allows disconnecting a user's Jira connection through a simple post message (Jira Plugin)EPSS 0.2%CVE-2025-3446MEDIUMMembers Without Guest Invite Permissions Can Add Guests to TeamsEPSS 0.2%CVE-2024-29215MEDIUMSlash commands run in channel without channel membership via playbook task commandsEPSS 0.2%CVE-2024-43813MEDIUMIDOR when marking read a user's channelEPSS 0.2%CVE-2026-1046HIGHArbitrary application execution via unvalidated server-controlled URLs in Help menuEPSS 0.2%CVE-2026-3495LOWUnescaped variables during error page compositionEPSS 0.2%CVE-2024-31859MEDIUMMember promoted to channel admin via playbooks run linking to channelEPSS 0.2%CVE-2026-10103MEDIUMAuthenticated remote cluster can modify or delete posts it does not own in Mattermost Connected Workspaces shared channelsEPSS 0.2%CVE-2025-32093MEDIUMSyatem admin profile modification by delegated granular administration roleEPSS 0.2%CVE-2025-1792LOWImproper Access Control in Mattermost Channel Member APIEPSS 0.2%CVE-2025-54478HIGHUnauthenticated Channel Subscription Edit in Mattermost Confluence PluginEPSS 0.2%CVE-2026-6062MEDIUMIDOR in Jira plugin subscription edit endpointEPSS 0.2%CVE-2025-27538LOWMFA Enforcement Bypass Allows Unauthorized Removal of MFA for Other UsersEPSS 0.2%