Github.Com Mattermost Mattermost-Plugin-Msteams vulnerabilities
2 known vulnerabilities affecting github.com/mattermost_mattermost-plugin-msteams.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-2476HIGH≥ 0, < 1.15.1-0.20260102165339-036c761bd3cb2026-03-16
CVE-2026-2476 [HIGH] CWE-200 Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values
Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values
Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606
ghsaosv
CVE-2025-27936MEDIUM≥ 0, < 2.1.02025-04-16
CVE-2025-27936 [MEDIUM] CWE-208 Mattermost vulnerable to Observable Timing Discrepancy
Mattermost vulnerable to Observable Timing Discrepancy
Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison.
ghsaosv