In Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, and 10.11.x <= 10.11.10 a medium severity vulnerability CVE-2026-2456 was detected. This vulnerability allows authenticated attackers to cause server memory exhaustion and denial of service (DoS) by leveraging a malicious integration server that returns excessively large responses from integration action endpoints. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2456.
Read more CommunicationIn Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, and 10.11.x <= 10.11.10 a medium severity vulnerability CVE-2026-2455 was detected. This vulnerability allows attackers to perform server-side request forgery (SSRF) attacks against internal services by exploiting improper canonicalization of IPv4-mapped IPv6 addresses during reserved IP validation. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2455.
Read more CommunicationIn Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, and 10.11.x <= 10.11.10 a high severity vulnerability CVE-2026-2454 was detected. This vulnerability allows a malicious user to cause server out-of-memory (OOM) errors and crash the server by sending corrupted Msgpack frames within WebSocket messages to the Calls plugin due to improper handling of incorrectly reported array lengths. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2454.
Read more CommunicationIn Mattermost versions 10.11.x <= 10.11.10 a medium severity vulnerability CVE-2026-1629 was detected. This vulnerability allows a user to continue viewing private channel content via previously cached permalink previews even after losing channel access, due to failure to invalidate cached preview data. To address this issue, users should upgrade Mattermost to versions 11.4.0 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1629.
Read more CommunicationIn Appsmith versions prior to 1.98 a medium severity vulnerability CVE-2026-34411 was detected. This vulnerability allows unauthenticated attackers to access sensitive instance management API endpoints, such as `/api/v1/consolidated-api/view` and `/api/v1/tenants/current`, to retrieve configuration metadata, license information, and unsalted SHA-256 hashes of admin email domains, which can be used for reconnaissance and targeted attacks. To address this issue, users should upgrade Appsmith to version 1.98 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-34411.
Read more Application DevelopmentIn Dolibarr versions 22.0.4 and prior a medium severity vulnerability CVE-2026-34036 was detected. This vulnerability allows an authenticated user with no specific privileges to read arbitrary non-PHP files on the server (e.g., .env, .htaccess, configuration backups, logs) by exploiting a Local File Inclusion (LFI) flaw in the `/core/ajax/selectobject.php` endpoint via the `objectdesc` parameter and a fail-open logic in the `restrictedArea()` access control function. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-34036.
Read more ERPIn Mattermost versions 11.3.x (≤ 11.3.0), 11.2.x (≤ 11.2.2), and 10.11.x (≤ 10.11.10) a medium severity vulnerability CVE-2026-2463 was detected. This vulnerability allows regular users to bypass access control restrictions and register unauthorized accounts using leaked invite IDs, due to improper filtering of invite identifiers based on user permissions. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2463.
Read more CommunicationIn Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, and 10.11.x <= 10.11.10 a medium severity vulnerability CVE-2026-2462 was detected. This vulnerability allows unauthenticated attackers to achieve remote code execution (RCE) and exfiltrate sensitive configuration data, including AWS and SMTP credentials, by uploading a malicious plugin on CI test instances with default admin credentials. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2462.
Read more CommunicationIn Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, and 10.11.x <= 10.11.10 a medium severity vulnerability CVE-2026-2458 was detected. This vulnerability allows removed team members to enumerate public channels within a private team via the channel search API endpoint due to improper validation of team membership. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2458.
Read more Communication