In Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, and 10.11.x <= 10.11.10 a medium severity vulnerability CVE-2026-2457 was detected. This vulnerability allows authenticated attackers to spoof permalink embeds and impersonate other users by submitting crafted metadata through the post update API endpoint due to insufficient sanitization of client-supplied input. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2457.
Read more CommunicationIn Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, and 10.11.x <= 10.11.10 a medium severity vulnerability CVE-2026-2456 was detected. This vulnerability allows authenticated attackers to cause server memory exhaustion and denial of service (DoS) by leveraging a malicious integration server that returns excessively large responses from integration action endpoints. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2456.
Read more CommunicationIn Mattermost versions 11.3.x (≤ 11.3.0), 11.2.x (≤ 11.2.2), and 10.11.x (≤ 10.11.10) a medium severity vulnerability CVE-2026-2463 was detected. This vulnerability allows regular users to bypass access control restrictions and register unauthorized accounts using leaked invite IDs, due to improper filtering of invite identifiers based on user permissions. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2463.
Read more CommunicationIn Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, and 10.11.x <= 10.11.10 a medium severity vulnerability CVE-2026-2462 was detected. This vulnerability allows unauthenticated attackers to achieve remote code execution (RCE) and exfiltrate sensitive configuration data, including AWS and SMTP credentials, by uploading a malicious plugin on CI test instances with default admin credentials. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2462.
Read more CommunicationIn Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, and 10.11.x <= 10.11.10 a medium severity vulnerability CVE-2026-2458 was detected. This vulnerability allows removed team members to enumerate public channels within a private team via the channel search API endpoint due to improper validation of team membership. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2458.
Read more CommunicationIn Mattermost versions 11.3.x (≤ 11.3.0), 11.2.x (≤ 11.2.2), and 10.11.x (≤ 10.11.10) a medium severity vulnerability CVE-2026-24692 was detected. This vulnerability allows guest users without read permissions to access posts and files in channels via the search API due to improper enforcement of access controls. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-24692.
Read more CommunicationIn Mattermost versions 11.3.x (≤ 11.3.0), 11.2.x (≤ 11.2.2), and 10.11.x (≤ 10.11.10) a high severity vulnerability CVE-2026-24458 was detected. This vulnerability allows an attacker to cause denial of service by submitting login attempts with multi-megabyte passwords, leading to excessive CPU and memory consumption due to improper input handling. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-24458.
Read more CommunicationIn Mattermost versions 10.11.x (≤ 10.11.10) a low severity vulnerability CVE-2026-22545 was detected. This vulnerability allows an authenticated attacker to change an account password without confirmation by falsely claiming a different authentication provider, due to improper validation of the user’s authentication method. To address this issue, users should upgrade Mattermost to versions 11.4.0 or 11.3.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-22545.
Read more CommunicationIn Mattermost versions 11.3.x (≤ 11.3.0) a medium severity vulnerability CVE-2026-2578 was detected. This vulnerability allows channel members to access unrevealed burn-on-read message contents via a WebSocket post deletion event, due to failure to preserve the redacted state of messages during deletion. To address this issue, users should upgrade Mattermost to versions 11.4.0 or 11.3.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2578.
Read more Communication