CVE Tools

Mattermost Server

467 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Mattermost Server, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.

Mattermost Server CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Mattermost Server CVEs per month
MonthCVEs
2024-104
2024-114
2024-124
2025-017
2025-026
2025-037
2025-0413
2025-059
2025-067
2025-073
2025-089
2025-096
2025-106
2025-1110
2025-1210
2026-012
2026-028
2026-0332
2026-044
2026-0532
2026-0615
2026-0713
2026-0812
2026-090

Severity

How the 467 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical174%
  • High6414%
  • Medium29663%
  • Low9019%

Latest CVEs

The 15 most recently published vulnerabilities affecting Mattermost Server.

  1. CVE-2026-9693Mattermost thread memberships persist after team removal, exposing private channel thread metadata on re-invite3.5
  2. CVE-2026-9859Mattermost Boards plugin didn’t enforce role-based authorization on board channel link allowing board editors to expose boards to arbitrary channels6.5
  3. CVE-2026-9816Insufficient server-side validation of board member role fields permits privilege escalation8.3
  4. CVE-2026-10080Boards plugin panics on WebSocket command with non-string field types6.5
  5. CVE-2026-10527Boards plugin retains Board Admin rights for users demoted to System Guest6.3
  6. CVE-2026-15754Missing per-channel team-scope check in ABAC access control policy unassign allows cross-team policy removal4.2
  7. CVE-2026-16044Insufficient validation of guest board admin privileges on archive import5.4
  8. CVE-2026-16045Delegated OAuth tokens could revoke unrelated OAuth application authorizations4.3
  9. CVE-2026-16047Board channel linking without read channel permission validation4.3
  10. CVE-2026-16046Missing run-state validation on finished playbook runs4.3
  11. CVE-2026-16048Channel member roles accept out-of-scope roles6.3
  12. CVE-2026-14298Boards archive import endpoint allows resource exhaustion via zip bomb and file size limit bypass in Mattermost6.5
  13. CVE-2026-7521SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory5.5
  14. CVE-2026-10819Mattermost Server Denial of Service via Animated GIF Emoji Upload6.5
  15. CVE-2026-10600Denial of service via unbounded document content extraction in Mattermost Server4.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store