In Mattermost versions 11.3.x <= 11.3.0 a medium severity vulnerability CVE-2026-2578 was detected. This vulnerability allows attackers to access unrevealed burn-on-read message contents via WebSocket post deletion events due to failure to preserve the redacted state during deletion. To address this issue, users should upgrade Mattermost to versions 11.4.0 or 11.3.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2578.
Read more CommunicationIn Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, and 10.11.x <= 10.11.10 a medium severity vulnerability CVE-2026-25780 was detected. This vulnerability allows authenticated attackers to cause server memory exhaustion and denial of service (DoS) by uploading a specially crafted DOC file due to unbounded memory allocation during file processing. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25780.
Read more CommunicationIn Mattermost versions 11.3.x (≤ 11.3.0), 11.2.x (≤ 11.2.2), and 10.11.x (≤ 10.11.10) a medium severity vulnerability CVE-2026-26246 was detected. This vulnerability allows an authenticated attacker to cause server memory exhaustion and denial of service by uploading a specially crafted PSD file, due to improper bounds on memory allocation during image processing. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26246.
Read more CommunicationIn Mattermost versions 10.11.x (≤ 10.11.10) a medium severity vulnerability CVE-2026-26230 was detected. This vulnerability allows team administrators to improperly demote members to the guest role due to insufficient validation of permission requirements in the team member roles API endpoint. To address this issue, users should upgrade Mattermost to versions 11.4.0 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26230.
Read more CommunicationIn Mattermost versions 11.3.x (≤ 11.3.0), 11.2.x (≤ 11.2.2), and 10.11.x (≤ 10.11.10) a medium severity vulnerability CVE-2026-25783 was detected. This vulnerability allows an authenticated attacker to trigger a denial of service by sending a specially crafted User-Agent header, causing a request panic due to improper validation of header tokens. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25783.
Read more CommunicationIn Mattermost Plugins versions 2.0.3.0 and earlier a medium severity vulnerability CVE-2026-2476 was detected. This vulnerability allows an attacker with access to support packets to obtain original plugin settings because sensitive configuration values are not properly masked in exported configuration data. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2476.
Read more CommunicationIn Mattermost Plugins versions 11.3, 11.0.3, 11.2.2, and 10.10.11.0 and earlier a medium severity vulnerability CVE-2026-2461 was detected. This vulnerability allows an authorized attacker with editor permissions to modify comments created by other board members due to missing authorization checks on comment block modifications. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2461.
Read more CommunicationIn Mattermost versions 11.3.x (≤ 11.3.0) and 11.2.x (≤ 11.2.2) a medium severity vulnerability CVE-2026-26304 was detected. This vulnerability allows team members to create unauthorized playbook runs via the playbook run API due to missing verification of the `run_create` permission for empty `playbookId`. To address this issue, users should upgrade Mattermost Server to version 11.3.1 or later (for 11.3.x branch) or version 11.2.3 or later (for 11.2.x branch). For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26304.
Read more Communication