Mattermost Ms Teams vulnerabilities
2 known vulnerabilities affecting mattermost/ms_teams.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-2476MEDIUMCVSS 4.3fixed in 2.3.12026-03-16
CVE-2026-2476 [MEDIUM] CWE-200 CVE-2026-2476: Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which all
Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606
nvd
CVE-2025-27936MEDIUMCVSS 5.9fixed in 2.1.02025-04-16
CVE-2025-27936 [MEDIUM] CWE-208 CVE-2025-27936: Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS
Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison.
nvd