Known Vulnerabilities for Mattermost by Jenkins
Listed below are 1 of the newest known vulnerabilities associated with "Mattermost" by "Jenkins".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-96260 json | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body ... | Not Provided | 2026-09-22 | 2026-09-23 |
| CVE-2026-96259 json | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-conn... | Not Provided | 2026-09-22 | 2026-09-23 |
| CVE-2026-95666 json | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-91181 json | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects r... | Not Provided | 2026-09-14 | 2026-09-16 |
| CVE-2026-86349 json | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting depth... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-86348 json | Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-84713 json | A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notific... | Not Provided | 2026-09-23 | 2026-09-25 |
| CVE-2026-82920 json | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the acce... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-75588 json | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is internal ... | Not Provided | 2026-09-17 | 2026-09-17 |
| CVE-2026-75587 json | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which ... | Not Provided | 2026-08-17 | 2026-08-18 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jenkins | Mattermost | 2.6.2 | |||
| Application | Jenkins | Mattermost | 2.6.1 | |||
| Application | Jenkins | Mattermost | 2.6 | |||
| Application | Jenkins | Mattermost | 2.5.2 | |||
| Application | Jenkins | Mattermost | 2.5.1 | |||
| Application | Jenkins | Mattermost | 2.5.0 | |||
| Application | Jenkins | Mattermost | 2.4.1 | |||
| Application | Jenkins | Mattermost | 2.4.0 | |||
| Application | Jenkins | Mattermost | 2.3.2 | |||
| Application | Jenkins | Mattermost | 2.3.1 | |||
| Application | Jenkins | Mattermost | 2.3.0 | |||
| Application | Jenkins | Mattermost | 2.2.0 | |||
| Application | Jenkins | Mattermost | 2.1.3 | |||
| Application | Jenkins | Mattermost | 2.1.2 | |||
| Application | Jenkins | Mattermost | 2.1.1 | |||
| Application | Jenkins | Mattermost | 2.1.0 | |||
| Application | Jenkins | Mattermost | 2.0.2 | |||
| Application | Jenkins | Mattermost | 2.0.1 | |||
| Application | Jenkins | Mattermost | 2.0 | |||
| Application | Jenkins | Mattermost | 1.5.3 |