Vulnerabilidades en Mattermost

438 resultados
Análisis Vexday

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2026-2476HIGHMS Teams plugin sensitive config values not properly masked in support packetsEPSS 0.2%CVE-2026-6673MEDIUMMattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud installEPSS 0.2%CVE-2025-46702MEDIUMMattermost Playbooks allows privilege escalation through improper access control in playbook run participant managementEPSS 0.2%CVE-2024-41926LOWMalicious remote can claim that a user was synced from another remoteEPSS 0.2%CVE-2025-6227LOWInvite token is used as part of the secure communicationEPSS 0.2%CVE-2025-2571MEDIUMGoogle OAuth Authentication Bypass for Converted Bot AccountsEPSS 0.2%CVE-2025-47700LOWAI plugin APIs can be triggered using post actionsEPSS 0.2%CVE-2026-4635MEDIUMPersistent notification timing attack causing server denial of serviceEPSS 0.2%CVE-2026-0999MEDIUMAuthentication bypass via userID login when email and username login are disabledEPSS 0.2%CVE-2026-4643LOWCalling window.close() from server-side content causes crash in the Mattermost Desktop AppEPSS 0.2%CVE-2026-5139MEDIUMGitLab Plugin Allows Non-Admin Users to Modify Default Instance ConfigurationEPSS 0.2%CVE-2026-2463MEDIUMUnauthorized access to invite ID during team creationEPSS 0.2%CVE-2025-47871MEDIUMMattermost Playbooks exposes private channel metadata to unauthorized users via run metadata APIEPSS 0.2%CVE-2025-11776MEDIUMGuest user can discover archived public channelsEPSS 0.2%CVE-2025-13324LOWLack of Invalidation of Legacy Remote Cluster Invite Tokens After ConfirmationEPSS 0.2%CVE-2026-27769LOWConnected Workspaces: Malicious remote server can manipulate arbitrary user's statusEPSS 0.2%CVE-2026-24692MEDIUMGuest users can bypass read permissions via search APIEPSS 0.2%CVE-2026-2456MEDIUMDenial of Service via Unbounded Memory Allocation in Integration ActionsEPSS 0.2%CVE-2026-2458MEDIUMUnauthorized channel enumeration in private teams after member removalEPSS 0.2%CVE-2026-6343MEDIUMMattermost Playbooks Plugin fails to enforce view permissions in list endpoints, allowing unauthorized access to public playbooksEPSS 0.2%