Github.Com Mattermost Mattermost Server V8 vulnerabilities
206 known vulnerabilities affecting github.com/mattermost_mattermost_server_v8.
Total CVEs
206
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH17MEDIUM134LOW48
Vulnerabilities
Page 6 of 11
CVE-2024-39839P4MEDIUM≥ 9.5.0, < 9.5.7≥ 9.7.0, < 9.7.6+2 more2024-08-01
CVE-2024-39839 [MEDIUM] CWE-284 Mattermost allows a user on a remote to set their remote username prop to an arbitrary string
Mattermost allows a user on a remote to set their remote username prop to an arbitrary string
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be
ghsaosv
CVE-2025-8402P4MEDIUM≥ 0, < 8.0.0-20250708173752-d6b35c41f0ae52025-08-21
CVE-2025-8402 [MEDIUM] CWE-476 Mattermost has Potential Server Crash due to Unvalidated Import Data
Mattermost has Potential Server Crash due to Unvalidated Import Data
Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature.
ghsaosv
CVE-2024-50052P4MEDIUM≥ 0, < 8.0.0-20240926115259-20ed58906adc2024-10-29
CVE-2024-50052 [MEDIUM] CWE-862 Mattermost server allows authenticated user to delete arbitrary post
Mattermost server allows authenticated user to delete arbitrary post
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.
ghsaosv
CVE-2025-3611P4LOW≥ 10.6.0-rc1, < 10.7.1≥ 10.0.0-rc1, < 10.5.4+2 more2025-05-30
CVE-2025-3611 [LOW] CWE-863 Mattermost fails to properly enforce access control restrictions for System Manager roles
Mattermost fails to properly enforce access control restrictions for System Manager roles
Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fails to properly enforce access control restrictions for System Manager roles, allowing authenticated users with System Manager privileges to view team details they should not have access to via direct API requests t
ghsaosv
CVE-2025-13870P4LOW≥ 0, < 8.0.0-20250905150616-ba86dfc5876b2025-12-02
CVE-2025-13870 [LOW] CWE-284 Mattermost fails to validate user permissions in Boards
Mattermost fails to validate user permissions in Boards
Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to
ghsaosv
CVE-2025-11776P4MEDIUM≥ 0, < 8.0.0-20250815165020-c8d66301415d2025-11-14
CVE-2025-11776 [MEDIUM] CWE-863 Mattermost fails to properly restrict access to archived channel search API
Mattermost fails to properly restrict access to archived channel search API
Mattermost versions < 11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint
ghsaosv
CVE-2024-41926P4MEDIUM≥ 9.5.0, < 9.5.7≥ 9.9.0, < 9.9.1+1 more2024-08-01
CVE-2024-41926 [MEDIUM] CWE-284 Mattermost allows remote actor to set arbitrary RemoteId values for synced users
Mattermost allows remote actor to set arbitrary RemoteId values for synced users
Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another remote.
ghsaosv
CVE-2026-6689P4MEDIUM≥ 8.0.0-20250731163400-5b955468ea1e, < 8.0.0-20260501144115-7d6816abdfd12026-06-12
CVE-2026-6689 [MEDIUM] CWE-862 Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fail to enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation (the check was only applied on upd
ghsa
CVE-2026-28759P4MEDIUM≥ 11.5.0, < 11.5.2≥ 10.11.0, < 10.11.14+2 more2026-05-18
CVE-2026-28759 [MEDIUM] CWE-863 Mattermost does not verify remote cluster channel access when processing shared channel membership removals
Mattermost does not verify remote cluster channel access when processing shared channel membership removals
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious re
ghsa
CVE-2026-28732P4MEDIUM≥ 11.5.0, < 11.5.2≥ 10.11.0, < 10.11.14+2 more2026-05-18
CVE-2026-28732 [MEDIUM] CWE-863 Mattermost doesn't enforce slash command trigger-word uniqueness during command updates
Mattermost doesn't enforce slash command trigger-word uniqueness during command updates
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom sl
ghsa
CVE-2026-2457P4MEDIUM≥ 0, < 8.0.0-20260123211116-9efe617be8b82026-03-16
CVE-2026-2457 [MEDIUM] CWE-346 Mattermost allows attackers to spoof permalink embeds
Mattermost allows attackers to spoof permalink embeds
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonating other users via crafted PUT requests to the post update API endpoint. Mattermost Advisory ID: MMSA-2025-00569
ghsaosv
CVE-2023-5968P4MEDIUM≥ 8.0.0, < 8.0.4≥ 8.1.0, < 8.1.3+2 more2023-11-06
CVE-2023-5968 [MEDIUM] CWE-116 Mattermost password hash disclosure vulnerability
Mattermost password hash disclosure vulnerability
Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body.
ghsaosv
CVE-2024-54682P4MEDIUM≥ 10.1.0, < 10.1.3≥ 10.0.0, < 10.0.3+2 more2024-12-16
CVE-2024-54682 [MEDIUM] CWE-409 Mattermost Data Amplification vulnerability
Mattermost Data Amplification vulnerability
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a DoS via zip bomb by importing data in a team they are a team admin.
ghsaosv
CVE-2024-41162P4MEDIUM≥ 9.5.0, < 9.5.7≥ 9.7.0, < 9.7.6+3 more2024-08-01
CVE-2024-41162 [MEDIUM] CWE-284 Mattermost allows a remote actor to make an arbitrary local channel read-only
Mattermost allows a remote actor to make an arbitrary local channel read-only
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only.
ghsaosv
CVE-2025-41423P4LOW≥ 0, < 8.0.0-20250218121836-2b5275d87136≥ 10.4.0+2 more2025-04-24
CVE-2025-41423 [LOW] CWE-863 Mattermost Playbooks fails to properly validate permissions
Mattermost Playbooks fails to properly validate permissions
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the Playbooks bot, even without channel access or appropriate permissions.
ghsaosv
CVE-2024-48872P4MEDIUM≥ 10.1.0, < 10.1.3≥ 10.0.0, < 10.0.3+2 more2024-12-16
CVE-2024-48872 [MEDIUM] CWE-362 Mattermost Race Condition vulnerability
Mattermost Race Condition vulnerability
Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrently checking and updating the failed login attempts. which allows an attacker to bypass of "Max failed attempts" restriction and send a big number of login attempts before being blocked via simultaneously sending multiple login requests
ghsaosv
CVE-2025-12559P4MEDIUM≥ 0, < 8.0.0-20251015091448-abbf01b9db452025-11-27
CVE-2025-12559 [MEDIUM] CWE-200 Mattermost fails to sanitize team email addresses
Mattermost fails to sanitize team email addresses
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
ghsaosv
CVE-2025-13767P4MEDIUM≥ 0, < 8.0.0-20251121122154-b57c297c6d72025-12-24
CVE-2025-13767 [MEDIUM] CWE-863 Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues
Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with acce
ghsaosv
CVE-2026-3433P4MEDIUM≥ 8.0.0-20250731163400-5b955468ea1e, < 8.0.0-20260504071740-9408b98025d72026-06-12
CVE-2026-3433 [MEDIUM] CWE-200 Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to restrict role_updated websocket event broadcasts to members of the affected team or channel, which allows an authenticated attacker with gues
ghsa
CVE-2026-0999P4MEDIUM≥ 0, < 8.0.0-20251212052346-61651b0df7ea2026-02-16
CVE-2026-0999 [MEDIUM] CWE-303 Mattermost fails to properly validate login method restrictions
Mattermost fails to properly validate login method restrictions
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to properly validate login method restrictions which allows an authenticated user to bypass SSO-only login requirements via userID-based authentication. Mattermost Advisory ID: MMSA-2025-00548
ghsaosv