Vulnerabilities
- CVSS
- 5.3 Medium
- Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N- Risk score
- 42.4
- Published
- 2026-06-12
- Status
- Published
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a username returned during bot registration belongs to a bot account, which allows an unprivileged attacker to intercept private messages sent by plugins via direct message channels by pre-registering a user account with a predictable plugin bot username.. Mattermost Advisory ID: MMSA-2026-00649
Coverage 1
vulnerability
Multiple vulnerabilities have been discovered in Mattermost products, including desktop apps and server versions. These vulnerabilities could allow an attacker to elevate privileges, compromise data confidentiality, and…
Advisories and references