In Mattermost versions 11.3.x (≤ 11.3.0), 11.2.x (≤ 11.2.2), and 10.11.x (≤ 10.11.10) a medium severity vulnerability CVE-2026-26246 was detected. This vulnerability allows an authenticated attacker to cause server memory exhaustion and denial of service by uploading a specially crafted PSD file, due to improper bounds on memory allocation during image processing. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26246.
Read more CommunicationIn Mattermost versions 10.11.x (≤ 10.11.10) a medium severity vulnerability CVE-2026-26230 was detected. This vulnerability allows team administrators to improperly demote members to the guest role due to insufficient validation of permission requirements in the team member roles API endpoint. To address this issue, users should upgrade Mattermost to versions 11.4.0 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26230.
Read more CommunicationIn Mattermost versions 11.3.x (≤ 11.3.0), 11.2.x (≤ 11.2.2), and 10.11.x (≤ 10.11.10) a medium severity vulnerability CVE-2026-25783 was detected. This vulnerability allows an authenticated attacker to trigger a denial of service by sending a specially crafted User-Agent header, causing a request panic due to improper validation of header tokens. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25783.
Read more CommunicationIn Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, and 10.11.x <= 10.11.10 a medium severity vulnerability CVE-2026-25780 was detected. This vulnerability allows authenticated attackers to cause server memory exhaustion and denial of service (DoS) by uploading a specially crafted DOC file due to unbounded memory allocation during file processing. To address this issue, users should upgrade Mattermost to versions 11.4.0, 11.3.1, 11.2.3 or 10.11.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25780.
Read more CommunicationIn Kanboard versions prior to 1.2.51 a high severity vulnerability CVE-2026-29056 was detected. This vulnerability allows an attacker who receives a user invite link to inject `role=app-admin` during registration, creating an administrator account and escalating privileges. To address this issue, users should upgrade Kanboard to version 1.2.51. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-29056.
Read more Project ManagementIn Kibana all versions from 8.0.0 up to and including 8.19.12, all versions from 9.0.0 up to and including 9.2.6, all versions from 9.3.0 up to and including 9.3.1 a medium severity vulnerability CVE-2026-26940 was detected. This vulnerability allows an authenticated user to send a specially crafted Timelion expression with an excessively large quantity value, causing internal series data properties to be overwritten and resulting in a Denial of Service via excessive resource allocation. To address this issue, users should upgrade Kibana to versions 8.19.13, 9.2.7 or 9.3.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26940.
Read more Data AnalyticsIn Kibana all versions from 8.0.0 up to and including 8.19.11, all versions from 9.0.0 up to and including 9.2.5, and version 9.3.0 a high severity vulnerability CVE-2026-26939 was detected. This vulnerability allows an authenticated attacker with rule management privileges to bypass server-side authorization in the Detection Rule Management system, enabling unauthorized configuration of endpoint response actions such as host isolation, process termination, and process suspension. To address this issue, users should upgrade Kibana to versions 8.19.12, 9.2.6 or 9.3.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26939.
Read more Data AnalyticsIn Mattermost Plugins versions 2.0.3.0 and earlier a medium severity vulnerability CVE-2026-2476 was detected. This vulnerability allows an attacker with access to support packets to obtain original plugin settings because sensitive configuration values are not properly masked in exported configuration data. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-2476.
Read more Communication