CVE-2026-6342
published 2026-05-18CVE-2026-6342: Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriately check for valid namespaces which allows plugin users to create subscriptions…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.15%
4.8th percentile
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriately check for valid namespaces which allows plugin users to create subscriptions to groups that were not whitelisted via creating groups that share the same prefix as a whitelisted group. Mattermost Advisory ID: MMSA-2026-00601
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mattermost | mattermost | <= 11.1.5 | — |
| mattermost | mattermost_server | 10.13.0 – 10.13.11 | — |
| mattermost | mattermost_server | 11.1.0 – 11.1.5 | — |
| mattermost | mattermost_server | 11.3.0 – 11.3.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x3f7-3cx7-2cw7: Mattermost Plugins versions <=11
ghsa_unreviewed·2026-05-18
CVE-2026-6342 [MEDIUM] CWE-863 GHSA-x3f7-3cx7-2cw7: Mattermost Plugins versions <=11
Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to appropriately check for valid namespaces which allows plugin users to create subscriptions to groups that were not whitelisted via creating groups that share the same prefix as a whitelisted group. Mattermost Advisory ID: MMSA-2026-00601
VulDB
Mattermost Plugins up to 11.5.1 Group authorization
vuldb·2026-05-18·CVSS 4.3
CVE-2026-6342 [MEDIUM] Mattermost Plugins up to 11.5.1 Group authorization
A vulnerability, which was classified as problematic, was found in Mattermost Plugins up to 11.5.1. This impacts an unknown function of the component Group Handler. Executing a manipulation can lead to incorrect authorization.
This vulnerability is registered as CVE-2026-6342. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-3889 thunderbird: Spoofing issue in Thunderbird
bugzilla·2026-03-24·CVSS 6.5
CVE-2026-3889 [MEDIUM] CVE-2026-3889 thunderbird: Spoofing issue in Thunderbird
CVE-2026-3889 thunderbird: Spoofing issue in Thunderbird
Spoofing issue in Thunderbird. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6188 https://access.redhat.com/errata/RHSA-2026:6188
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:6342 https://access.redhat.com/errata/RHSA-2026:6342
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2026:6917 https://access.redhat.com/errata/RHSA-2026:6917
Bugzilla
CVE-2026-4371 thunderbird: Out of bounds read in IMAP parsing
bugzilla·2026-03-24·CVSS 7.4
CVE-2026-4371 [HIGH] CVE-2026-4371 thunderbird: Out of bounds read in IMAP parsing
CVE-2026-4371 thunderbird: Out of bounds read in IMAP parsing
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6188 https://access.redhat.com/errata/RHSA-2026:6188
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:6342 https://access.redhat.com/errata/RHSA-2026:6342
---
This issue has been address
2026-05-18
Published