Vulnerabilidades em Mattermost

438 resultados
Análise Vexday

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2026-6689MEDIUM*Missing* {{invite_user}} *permission check on team creation allows unprivileged users to set open-invite and allowed-domains team settings*EPSS 0.2%CVE-2026-6342MEDIUMGroup prefix matching bypass for subscriptionsEPSS 0.2%CVE-2026-3637MEDIUMMattermost fails to enforce create_post permission when editing postsEPSS 0.2%CVE-2026-0997MEDIUMMattermost Zoom Plugin channel preference API lacks authorization checksEPSS 0.2%CVE-2026-28759MEDIUMInsufficient authorization in shared channel membership sync allows remote cluster to remove users from arbitrary channelsEPSS 0.2%CVE-2025-12756MEDIUMInsecure Direct Object Reference in Mattermost Boards Plugin Enables Unauthorised Comment DeletionEPSS 0.2%CVE-2026-3473MEDIUMImproper file ownership validation in the Boards API allows unauthorised file accessEPSS 0.1%CVE-2024-46872MEDIUMClient-Side Path Traversal Leading to CSRF in PlaybooksEPSS 0.1%CVE-2026-22545LOWPassword Change Bypass via Auth Switch EndpointEPSS 0.1%CVE-2025-41436LOWUnauthorized access to archived channel content via threads interfaceEPSS 0.1%CVE-2025-64641MEDIUMMattermost Jira plugin crafted action leaks Jira issue detailsEPSS 0.1%CVE-2026-3590MEDIUMRace Condition in Guest Magic Link Authentication Allows Token ReuseEPSS 0.1%CVE-2025-13352LOWMattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijackingEPSS 0.1%CVE-2025-55074LOWChannel member objects leak read statusEPSS 0.1%CVE-2023-5339MEDIUMMattermost Desktop logs all keystrokes during initial run after fresh installation EPSS 0.1%CVE-2026-3495LOWUnescaped variables during error page compositionEPSS 0.1%CVE-2026-4286LOWPlaybooks Plugin fails to validate team transfers, allowing unauthorized removal of member access via playbook updateEPSS 0.1%CVE-2026-4273LOWInsufficient token rotation validation in remote cluster invite confirmationEPSS 0.1%CVE-2025-9078MEDIUMWeak cache keys lead to post IDOR and link preview poisoningEPSS 0.1%CVE-2026-4274MEDIUMInsufficient authorization in shared channel membership sync grants team-level access instead of channel-level accessEPSS 0.1%