cbcvebase.
CVE-2026-3495
published 2026-05-18

CVE-2026-3495: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition…

PriorityP422medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.14%
4.0th percentile
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some malicious code via injecting some JS as part of those values.. Mattermost Advisory ID: MMSA-2026-00622

Affected

8 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 0 < 5.3.2-0.20260310115442-5a1ea95044dc5.3.2-0.20260310115442-5a1ea95044dc
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20260310115442-5a1ea95044d8.0.0-20260310115442-5a1ea95044d
github.commattermost_mattermost_server_v8>= 10.11.0 < 10.11.1410.11.14
github.commattermost_mattermost_server_v8>= 11.5.0 < 11.5.211.5.2
mattermostmattermost10.11.0 – 10.11.13
mattermostmattermost11.5.0 – 11.5.1
mattermostmattermost_server>= 10.11.0 < 10.11.1410.11.14
mattermostmattermost_server>= 11.5.0 < 11.5.211.5.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.