cbcvebase.

Github.Com Mattermost Mattermost Server V8 vulnerabilities

206 known vulnerabilities affecting github.com/mattermost_mattermost_server_v8.

Total CVEs
206
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH17MEDIUM134LOW48

Vulnerabilities

Page 7 of 11
CVE-2026-2463P4MEDIUM≥ 0, < 8.0.0-20260105134819-cc427af41b2a2026-03-16
CVE-2026-2463 [MEDIUM] CWE-862 Mattermost fails to filter invite IDs based on user permissions Mattermost fails to filter invite IDs based on user permissions Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs during team creation. Mattermost Advisory ID: MMSA-2025-00565
ghsaosv
CVE-2026-2455P4MEDIUM≥ 0, < 8.0.0-20260129133647-5d787969c2d52026-03-16
CVE-2026-2455 [MEDIUM] CWE-918 Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation which allows an attacker to perform SSRF attacks against internal services via IPv4-mapped IPv6 literals (e.g., [::ffff:127.0.0.1])..
ghsaosv
CVE-2026-2458P4MEDIUM≥ 0, < 8.0.0-20260113182106-a18b80ba4c322026-03-16
CVE-2026-2458 [MEDIUM] CWE-862 Mattermost allows a removed team member to enumerate all public channels within a private team Mattermost allows a removed team member to enumerate all public channels within a private team Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership when searching channels which allows a removed team member to enumerate all public channels within a private team via the channel search API endpoint. Mattermos
ghsaosv
CVE-2026-24692P4MEDIUM≥ 0, < 8.0.0-20260107142155-0481bd1fb0452026-03-16
CVE-2026-24692 [MEDIUM] CWE-863 Mattermost fails to properly enforce read permissions in search API endpoints Mattermost fails to properly enforce read permissions in search API endpoints Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly enforce read permissions in search API endpoints which allows guest users without read permissions to access posts and files in channels via search API requests. Mattermost Advisory ID: MMSA-2025-00554
ghsaosv
CVE-2024-46872P4MEDIUM≥ 0, < 8.0.0-20240926115259-20ed58906adc2024-10-29
CVE-2024-46872 [MEDIUM] CWE-352 Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks
ghsaosv
CVE-2026-4055P4MEDIUM≥ 8.0.0-20260304132957-9f2616376582, < 8.0.0-20260320113102-f2b3d1c6a9452026-05-21
CVE-2026-4055 [MEDIUM] CWE-863 Mattermost has an Incorrect Authorization issue Mattermost has an Incorrect Authorization issue Mattermost versions 11.5.x <= 11.5.1 fail to validate team-level run_create permission against the target team when creating a playbook run which allows an authenticated team member to create runs in teams where they lack permission via specifying a different team ID in the run creation API request. Mattermost Advisory ID: MMSA-2026-00629.
ghsa
CVE-2026-4286P4LOW≥ 11.5.0, < 11.5.2≥ 10.11.0, < 10.11.142026-05-18
CVE-2026-4286 [LOW] CWE-863 Mattermost doesn't check if {{team_id}} was being changed when updating playbooks Mattermost doesn't check if {{team_id}} was being changed when updating playbooks Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating playbooks, allowing users with only {{Manage Playbook Configurations}} permission to change a playbook's team, bypassing manage members restriction via PUT api. Mattermost Advisory ID: MMS
ghsa
CVE-2026-4273P4LOW≥ 11.5.0, < 11.5.2≥ 10.11.0, < 10.11.14+1 more2026-05-18
CVE-2026-4273 [LOW] CWE-863 Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation which allows an authentic
ghsa
CVE-2023-5194P4MEDIUM≥ 8.1.0, < 8.1.1≥ 8.0.0, < 8.0.22023-09-29
CVE-2023-5194 [MEDIUM] CWE-863 Mattermost Incorrect Authorization vulnerability Mattermost Incorrect Authorization vulnerability Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for a system/user manager to demote / deactivate another manager
ghsaosv
CVE-2024-23488P4LOW≥ 9.0.0, < 9.4.2≥ 0, < 8.1.92024-02-29
CVE-2024-23488 [LOW] CWE-284 Mattermost fails to properly restrict the access of files attached to posts Mattermost fails to properly restrict the access of files attached to posts Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members being able to access files of archived channels even if the “Allow users to view archived channels” option is disabled.
ghsaosv
CVE-2025-10545P4LOW≥ 0, < 8.0.0-20250820115038-ff30b84049f02025-10-16
CVE-2025-10545 [LOW] CWE-863 Mattermost has an Incorrect Authorization vulnerability Mattermost has an Incorrect Authorization vulnerability Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team members to their private channels via the `/api/v4/channels/{channel_id}/members` endpoint
ghsaosv
CVE-2025-2527P4MEDIUM≥ 10.5.0, < 10.5.3≥ 9.11.0, < 9.11.12+1 more2025-05-15
CVE-2025-2527 [MEDIUM] CWE-863 Mattermost Fails to Verify User's Permissions When Accessing Groups Mattermost Fails to Verify User's Permissions When Accessing Groups Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing groups, which allows an attacker to view group information via an API request.
ghsaosv
CVE-2026-25783P4MEDIUM≥ 0, < 8.0.0-20260129181235-1346cf529aef2026-03-16
CVE-2026-25783 [MEDIUM] CWE-1287 Mattermost fails to properly validate User-Agent header tokens Mattermost fails to properly validate User-Agent header tokens Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a specially crafted User-Agent header. Mattermost Advisory ID: MMSA-2026-00586
ghsaosv
CVE-2025-41443P4MEDIUM≥ 0, < 8.0.0-20250822090405-e8c7e7d0252b2025-10-16
CVE-2025-41443 [MEDIUM] CWE-862 Mattermost has a Missing Authorization vulnerability Mattermost has a Missing Authorization vulnerability Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessing channel information which allows guest users to discover active public channels and their metadata via the `/api/v4/teams/{team_id}/channels/ids` endpoint
ghsaosv
CVE-2024-43780P4MEDIUM≥ 9.5.0, < 9.5.8≥ 9.10.0, < 9.10.1+2 more2024-08-22
CVE-2024-43780 [MEDIUM] CWE-284 Mattermost allows guest user with read access to upload files to a channel Mattermost allows guest user with read access to upload files to a channel Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.
ghsaosv
CVE-2025-3228P4MEDIUM≥ 0, < 8.0.0-20250520060012-d0380305ef7a≥ 10.5.0, < 10.5.6+4 more2025-06-20
CVE-2025-3228 [MEDIUM] CWE-863 Mattermost allows an unauthorized Guest user access to Playbook Mattermost allows an unauthorized Guest user access to Playbook Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly retrieve requestorInfo from playbooks handler for guest users which allows an attacker access to the playbook run.
ghsaosv
CVE-2025-2424P4LOW≥ 10.5.0, < 10.5.2≥ 9.11.0, < 9.11.10+1 more2025-04-14
CVE-2025-2424 [LOW] CWE-863 Mattermost Incorrect Authorization vulnerability Mattermost Incorrect Authorization vulnerability Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
ghsaosv
CVE-2026-3115P4MEDIUM≥ 11.4.0, < 11.4.1≥ 11.3.0-rc1, < 11.3.2+3 more2026-03-26
CVE-2026-3115 [MEDIUM] CWE-863 Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restrictions when retrieving group member IDs, which allows authenticated guest users to enumerate user IDs outside their allowed visibility scop
ghsaosv
CVE-2025-24839P4LOW≥ 10.5.0, < 10.5.2≥ 10.4.0, < 10.4.4+2 more2025-04-16
CVE-2025-24839 [LOW] CWE-863 Mattermost Incorrect Authorization vulnerability Mattermost Incorrect Authorization vulnerability Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering AI responses. This vulnerability allows users without access to the AI bot to activate it by attaching the activate_ai override property to a post via the Wrangler plugin, provided both the AI and Wrangler plugins are enabled.
ghsaosv
CVE-2025-4128P4LOW≥ 0, < 8.0.0-20250422131222-701ddc896a102025-06-11
CVE-2025-4128 [LOW] CWE-863 Mattermost allows guest users to view information about public teams they are not members of Mattermost allows guest users to view information about public teams they are not members of Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about public teams they are not members of via a direct API call to /api/v4/teams/{team_id}.
ghsaosv
Github.Com Mattermost Mattermost Server V8 vulnerabilities | cvebase