Mattermost vulnerabilities
14 CVEs tracked
Mattermost appears in our reports with multiple vulnerabilities related to privilege escalation, information disclosure, and Denial of Service (DoS) exploitable by authenticated users. Key issues include authorization flaws allowing disclosure of private channel membership (CVE-2026-16047) and permission escalation for channel admins (CVE-2026-16048), alongside resource exhaustion attacks via animated GIF uploads (CVE-2026-10819) and server-side document extraction (CVE-2026-10600). Defenders should prioritize updating to the latest patched versions of Mattermost and monitoring server resource consumption to mitigate these risks.
Azərbaycanca: Hesabatlarımızda Mattermost məhsulunda autentifikasiya olunmuş istifadəçilər tərəfindən həyata keçirilə bilən bir sıra imtiyaz artırma, məxfi məlumatların ifşası və xidmətin dayandırılması (DoS) zəiflikləri müşahidə olunur. Xüsusilə, qapalı kanal üzvlüyünün aşkarlanması (CVE-2026-16047) və kanal administratorlarının əlavə icazələr əldə etməsi (CVE-2026-16048) kimi səlahiyyət idarəetmə problemləri ilə yanaşı, animasiyalı GIF faylları (CVE-2026-10819) və sənəd məzmununun çıxarılması (CVE-2026-10600) kimi resurs tükənməsi hücumları diqqət çəkir. Müdafiəçilər istifadə olunan Mattermost versiyalarının bu kritik boşluqları aradan qaldıran ən son stabil versiyalara yenilənməsini və server resurslarının monitorinqini prioritetləşdirməlidir.
This vendor's CVEs14
- CVE-2026-75587EPSS 0.09%
- CVE-2026-16049EPSS 0.22%
- CVE-2026-16048EPSS 0.15%
- CVE-2026-16047EPSS 0.16%
- CVE-2026-16046EPSS 0.15%
- CVE-2026-16045EPSS 0.19%
- CVE-2026-16044EPSS 0.17%
- CVE-2026-15754EPSS 0.15%
- CVE-2026-14298EPSS 0.24%
- CVE-2026-10819EPSS 0.24%
- CVE-2026-10600EPSS 0.22%
- CVE-2026-10527EPSS 0.15%
- CVE-2026-9693EPSS 0.16%
- CVE-2026-7521EPSS 0.28%
This hub is built from skopnix's own reporting on Mattermost: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.