{"schema_version":1,"title":"github.com/mattermost/mattermost-server/v6 (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 188 vulnerabilities in github.com/mattermost/mattermost-server/v6 (Go): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-3114, was published on 25 June 2026.","url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v6","json_url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v6.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v6","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":188,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":70},"latest":[{"cve":"CVE-2026-3114","cvss":3.1,"epss":0.0042,"slug":"cve-2026-3114-mattermost-doesn-t-validate-decompressed-archive-entry-sizes","title":"GO-2026-5663 - Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server","severity":"low","exploited":false,"published_at":"2026-06-25T22:34:38+00:00","url":"https://junglewise.ai/threats/cve-2026-3114-mattermost-doesn-t-validate-decompressed-archive-entry-sizes"},{"cve":"CVE-2026-27659","cvss":3.1,"epss":0.0022,"slug":"cve-2026-27659-mattermost-doesn-t-properly-validate-csrf-tokens","title":"GO-2026-5629 - Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server","severity":"low","exploited":false,"published_at":"2026-06-25T22:34:34+00:00","url":"https://junglewise.ai/threats/cve-2026-27659-mattermost-doesn-t-properly-validate-csrf-tokens"},{"cve":"CVE-2026-3115","cvss":3.1,"epss":0.0027,"slug":"cve-2026-3115-mattermost-allows-authenticated-guest-users-to-enumerate-user-ids","title":"GO-2026-5512 - Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost","severity":"low","exploited":false,"published_at":"2026-06-25T22:34:34+00:00","url":"https://junglewise.ai/threats/cve-2026-3115-mattermost-allows-authenticated-guest-users-to-enumerate-user-ids"},{"cve":"CVE-2026-28741","cvss":3.1,"epss":0.0018,"slug":"cve-2026-28741-mattermost-doesn-t-validate-csrf-tokens-on-an-authentication","title":"GO-2026-5495 - Mattermost doesn't validate CSRF tokens on an authentication endpoint in github.com/mattermost/mattermost-server","severity":"low","exploited":false,"published_at":"2026-06-25T22:34:31+00:00","url":"https://junglewise.ai/threats/cve-2026-28741-mattermost-doesn-t-validate-csrf-tokens-on-an-authentication"},{"cve":"CVE-2026-4274","cvss":3.1,"epss":0.0023,"slug":"cve-2026-4274-mattermost-has-an-incorrect-authorization-issue","title":"GO-2026-5393 - Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server","severity":"low","exploited":false,"published_at":"2026-06-25T18:43:19+00:00","url":"https://junglewise.ai/threats/cve-2026-4274-mattermost-has-an-incorrect-authorization-issue"},{"cve":"CVE-2026-27656","cvss":3.1,"epss":0.0031,"slug":"cve-2026-27656-mattermost-allows-attackers-to-take-over-arbitrary-user-accounts","title":"GO-2026-5360 - Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/matt","severity":"low","exploited":false,"published_at":"2026-06-25T18:43:19+00:00","url":"https://junglewise.ai/threats/cve-2026-27656-mattermost-allows-attackers-to-take-over-arbitrary-user-accounts"},{"cve":"CVE-2026-20719","cvss":3.1,"epss":0.0035,"slug":"cve-2026-20719-mattermost-authenticated-dos-through-failure-to-prevent-rendering","title":"GO-2026-5245 - Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds in github.com/mattermost/mattermost-serve","severity":"low","exploited":false,"published_at":"2026-06-25T18:43:15+00:00","url":"https://junglewise.ai/threats/cve-2026-20719-mattermost-authenticated-dos-through-failure-to-prevent-rendering"},{"cve":"CVE-2026-3112","cvss":3.1,"epss":0.0047,"slug":"cve-2026-3112-mattermost-allows-system-administrators-to-read-arbitrary-host","title":"GO-2026-5092 - Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermos","severity":"low","exploited":false,"published_at":"2026-06-25T18:26:48+00:00","url":"https://junglewise.ai/threats/cve-2026-3112-mattermost-allows-system-administrators-to-read-arbitrary-host"},{"cve":"CVE-2026-3108","cvss":3.1,"epss":0.0034,"slug":"cve-2026-3108-mattermost-allows-attackers-to-manipulate-administrator-terminals","title":"GO-2026-5067 - Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.co","severity":"low","exploited":false,"published_at":"2026-06-25T18:26:48+00:00","url":"https://junglewise.ai/threats/cve-2026-3108-mattermost-allows-attackers-to-manipulate-administrator-terminals"},{"cve":"CVE-2026-7387","cvss":8.8,"epss":0.0042,"slug":"cve-2026-7387-mattermost-privilege-escalation-in-group-syncable-link-and-patch","title":"Mattermost privilege escalation in group syncable link and patch endpoints","severity":"high","exploited":false,"published_at":"2026-06-12T17:16:27.653+00:00","url":"https://junglewise.ai/threats/cve-2026-7387-mattermost-privilege-escalation-in-group-syncable-link-and-patch"},{"cve":"CVE-2026-7184","cvss":6.5,"epss":0.0044,"slug":"cve-2026-7184-mattermost-sensitive-information-disclosure-in-remote-cluster-api","title":"Mattermost sensitive information disclosure in Remote Cluster API","severity":"medium","exploited":false,"published_at":"2026-06-12T17:16:27.53+00:00","url":"https://junglewise.ai/threats/cve-2026-7184-mattermost-sensitive-information-disclosure-in-remote-cluster-api"},{"cve":"CVE-2026-6961","cvss":7.6,"epss":0.0045,"slug":"cve-2026-6961-mattermost-path-traversal-in-shared-channel-file-sync","title":"Mattermost path traversal in shared channel file sync","severity":"high","exploited":false,"published_at":"2026-06-12T17:16:27.41+00:00","url":"https://junglewise.ai/threats/cve-2026-6961-mattermost-path-traversal-in-shared-channel-file-sync"},{"cve":"CVE-2026-6739","cvss":6.7,"epss":0.0046,"slug":"cve-2026-6739-mattermost-privilege-escalation-in-role-patch-api","title":"Mattermost privilege escalation in role patch API","severity":"medium","exploited":false,"published_at":"2026-06-12T17:16:27.29+00:00","url":"https://junglewise.ai/threats/cve-2026-6739-mattermost-privilege-escalation-in-role-patch-api"},{"cve":"CVE-2026-6689","cvss":4.3,"epss":0.0025,"slug":"cve-2026-6689-mattermost-missing-authorization-for-invite-settings-during-team","title":"Mattermost missing authorization for invite settings during team creation","severity":"medium","exploited":false,"published_at":"2026-06-12T17:16:27.18+00:00","url":"https://junglewise.ai/threats/cve-2026-6689-mattermost-missing-authorization-for-invite-settings-during-team"},{"cve":"CVE-2026-6046","cvss":5.3,"epss":0.003,"slug":"cve-2026-6046-mattermost-message-interception-via-predictable-bot-usernames","title":"Mattermost message interception via predictable bot usernames","severity":"medium","exploited":false,"published_at":"2026-06-12T17:16:26.957+00:00","url":"https://junglewise.ai/threats/cve-2026-6046-mattermost-message-interception-via-predictable-bot-usernames"},{"cve":"CVE-2026-3433","cvss":4.3,"epss":0.003,"slug":"cve-2026-3433-mattermost-information-disclosure-in-role-updated-websocket-events","title":"Mattermost information disclosure in role_updated WebSocket events","severity":"medium","exploited":false,"published_at":"2026-06-12T17:16:22.467+00:00","url":"https://junglewise.ai/threats/cve-2026-3433-mattermost-information-disclosure-in-role-updated-websocket-events"},{"cve":"CVE-2026-4915","cvss":6.5,"epss":0.0036,"slug":"cve-2026-4915-mattermost-server-denial-of-service-via-null-webhook-attachment","title":"Mattermost Server denial of service via null webhook attachment","severity":"medium","exploited":false,"published_at":"2026-05-25T08:16:24.897+00:00","url":"https://junglewise.ai/threats/cve-2026-4915-mattermost-server-denial-of-service-via-null-webhook-attachment"},{"cve":"CVE-2026-5740","cvss":7.5,"epss":0.0057,"slug":"cve-2026-5740-mattermost-server-denial-of-service-via-msgpack-websocket-frames","title":"Mattermost Server denial of service via msgpack WebSocket frames","severity":"high","exploited":false,"published_at":"2026-05-22T11:16:23.163+00:00","url":"https://junglewise.ai/threats/cve-2026-5740-mattermost-server-denial-of-service-via-msgpack-websocket-frames"},{"cve":"CVE-2026-4055","cvss":4.3,"epss":0.0025,"slug":"cve-2026-4055-mattermost-incorrect-authorization-in-playbook-run-creation","title":"Mattermost incorrect authorization in Playbook run creation","severity":"medium","exploited":false,"published_at":"2026-05-21T08:16:23.13+00:00","url":"https://junglewise.ai/threats/cve-2026-4055-mattermost-incorrect-authorization-in-playbook-run-creation"},{"cve":"CVE-2026-6346","cvss":8.7,"epss":0.0041,"slug":"cve-2026-6346-mattermost-sensitive-information-disclosure-in-support-packet","title":"Mattermost sensitive information disclosure in support packet generation","severity":"high","exploited":false,"published_at":"2026-05-18T09:16:24+00:00","url":"https://junglewise.ai/threats/cve-2026-6346-mattermost-sensitive-information-disclosure-in-support-packet"},{"cve":"CVE-2026-6345","cvss":6.5,"epss":0.0039,"slug":"cve-2026-6345-mattermost-password-disclosure-in-user-creation","title":"Mattermost password disclosure in user creation","severity":"medium","exploited":false,"published_at":"2026-05-18T09:16:23.853+00:00","url":"https://junglewise.ai/threats/cve-2026-6345-mattermost-password-disclosure-in-user-creation"},{"cve":"CVE-2026-6343","cvss":4.3,"epss":0.0027,"slug":"cve-2026-6343-mattermost-incorrect-authorization-in-playbooks-via-get-endpoint","title":"Mattermost Incorrect Authorization in Playbooks via /get endpoint","severity":"medium","exploited":false,"published_at":"2026-05-18T09:16:23.713+00:00","url":"https://junglewise.ai/threats/cve-2026-6343-mattermost-incorrect-authorization-in-playbooks-via-get-endpoint"},{"cve":"CVE-2026-6339","cvss":4.3,"epss":0.0016,"slug":"cve-2026-6339-mattermost-origin-validation-error-in-burn-on-read-reveal-endpoint","title":"Mattermost origin validation error in burn-on-read reveal endpoint","severity":"medium","exploited":false,"published_at":"2026-05-18T09:16:23.573+00:00","url":"https://junglewise.ai/threats/cve-2026-6339-mattermost-origin-validation-error-in-burn-on-read-reveal-endpoint"},{"cve":"CVE-2026-6333","cvss":3.5,"epss":0.0022,"slug":"cve-2026-6333-mattermost-server-ssrf-via-host-header-in-slash-commands","title":"Mattermost Server SSRF via Host header in slash commands","severity":"low","exploited":false,"published_at":"2026-05-18T09:16:23.43+00:00","url":"https://junglewise.ai/threats/cve-2026-6333-mattermost-server-ssrf-via-host-header-in-slash-commands"},{"cve":"CVE-2026-5163","cvss":6.5,"epss":0.0034,"slug":"cve-2026-5163-mattermost-missing-authorization-in-ai-assisted-message-rewrites","title":"Mattermost missing authorization in AI-assisted message rewrites","severity":"medium","exploited":false,"published_at":"2026-05-18T09:16:23.273+00:00","url":"https://junglewise.ai/threats/cve-2026-5163-mattermost-missing-authorization-in-ai-assisted-message-rewrites"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/mattermost/mattermost-server (Go)","slug":"github-com-mattermost-mattermost-server","vulnerabilities":274,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server"},{"name":"github.com/mattermost/mattermost-server/v5 (Go)","slug":"github-com-mattermost-mattermost-server-v5","vulnerabilities":186,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v5"},{"name":"github.com/mattermost/mattermost/server/v8 (Go)","slug":"github-com-mattermost-mattermost-server-v8","vulnerabilities":182,"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v8"},{"name":"stdlib (Go)","slug":"go-stdlib","vulnerabilities":161,"url":"https://junglewise.ai/threats/technologies/go-stdlib"},{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":158,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":128,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/traefik/traefik (Go)","slug":"github-com-traefik-traefik","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik"},{"name":"github.com/usememos/memos (Go)","slug":"github-com-usememos-memos","vulnerabilities":75,"url":"https://junglewise.ai/threats/technologies/github-com-usememos-memos"},{"name":"github.com/traefik/traefik/v2 (Go)","slug":"github-com-traefik-traefik-v2","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v2"},{"name":"github.com/traefik/traefik/v3 (Go)","slug":"github-com-traefik-traefik-v3","vulnerabilities":68,"url":"https://junglewise.ai/threats/technologies/github-com-traefik-traefik-v3"},{"name":"github.com/hashicorp/vault (Go)","slug":"github-com-hashicorp-vault","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/github-com-hashicorp-vault"}],"technology":{"hub":true,"name":"github.com/mattermost/mattermost-server/v6 (Go)","slug":"github-com-mattermost-mattermost-server-v6","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/github-com-mattermost-mattermost-server-v6"},"most_severe":[{"cve":"CVE-2026-7387","cvss":8.8,"epss":0.0042,"slug":"cve-2026-7387-mattermost-privilege-escalation-in-group-syncable-link-and-patch","title":"Mattermost privilege escalation in group syncable link and patch endpoints","severity":"high","exploited":false,"published_at":"2026-06-12T17:16:27.653+00:00","url":"https://junglewise.ai/threats/cve-2026-7387-mattermost-privilege-escalation-in-group-syncable-link-and-patch"},{"cve":"CVE-2026-6346","cvss":8.7,"epss":0.0041,"slug":"cve-2026-6346-mattermost-sensitive-information-disclosure-in-support-packet","title":"Mattermost sensitive information disclosure in support packet generation","severity":"high","exploited":false,"published_at":"2026-05-18T09:16:24+00:00","url":"https://junglewise.ai/threats/cve-2026-6346-mattermost-sensitive-information-disclosure-in-support-packet"},{"cve":"CVE-2026-6961","cvss":7.6,"epss":0.0045,"slug":"cve-2026-6961-mattermost-path-traversal-in-shared-channel-file-sync","title":"Mattermost path traversal in shared channel file sync","severity":"high","exploited":false,"published_at":"2026-06-12T17:16:27.41+00:00","url":"https://junglewise.ai/threats/cve-2026-6961-mattermost-path-traversal-in-shared-channel-file-sync"},{"cve":"CVE-2026-5740","cvss":7.5,"epss":0.0057,"slug":"cve-2026-5740-mattermost-server-denial-of-service-via-msgpack-websocket-frames","title":"Mattermost Server denial of service via msgpack WebSocket frames","severity":"high","exploited":false,"published_at":"2026-05-22T11:16:23.163+00:00","url":"https://junglewise.ai/threats/cve-2026-5740-mattermost-server-denial-of-service-via-msgpack-websocket-frames"},{"cve":"CVE-2026-6739","cvss":6.7,"epss":0.0046,"slug":"cve-2026-6739-mattermost-privilege-escalation-in-role-patch-api","title":"Mattermost privilege escalation in role patch API","severity":"medium","exploited":false,"published_at":"2026-06-12T17:16:27.29+00:00","url":"https://junglewise.ai/threats/cve-2026-6739-mattermost-privilege-escalation-in-role-patch-api"},{"cve":"CVE-2026-7184","cvss":6.5,"epss":0.0044,"slug":"cve-2026-7184-mattermost-sensitive-information-disclosure-in-remote-cluster-api","title":"Mattermost sensitive information disclosure in Remote Cluster API","severity":"medium","exploited":false,"published_at":"2026-06-12T17:16:27.53+00:00","url":"https://junglewise.ai/threats/cve-2026-7184-mattermost-sensitive-information-disclosure-in-remote-cluster-api"},{"cve":"CVE-2026-6345","cvss":6.5,"epss":0.0039,"slug":"cve-2026-6345-mattermost-password-disclosure-in-user-creation","title":"Mattermost password disclosure in user creation","severity":"medium","exploited":false,"published_at":"2026-05-18T09:16:23.853+00:00","url":"https://junglewise.ai/threats/cve-2026-6345-mattermost-password-disclosure-in-user-creation"},{"cve":"CVE-2026-4915","cvss":6.5,"epss":0.0036,"slug":"cve-2026-4915-mattermost-server-denial-of-service-via-null-webhook-attachment","title":"Mattermost Server denial of service via null webhook attachment","severity":"medium","exploited":false,"published_at":"2026-05-25T08:16:24.897+00:00","url":"https://junglewise.ai/threats/cve-2026-4915-mattermost-server-denial-of-service-via-null-webhook-attachment"},{"cve":"CVE-2026-5163","cvss":6.5,"epss":0.0034,"slug":"cve-2026-5163-mattermost-missing-authorization-in-ai-assisted-message-rewrites","title":"Mattermost missing authorization in AI-assisted message rewrites","severity":"medium","exploited":false,"published_at":"2026-05-18T09:16:23.273+00:00","url":"https://junglewise.ai/threats/cve-2026-5163-mattermost-missing-authorization-in-ai-assisted-message-rewrites"},{"cve":"CVE-2026-3590","cvss":6.5,"epss":0.0022,"slug":"cve-2026-3590-mattermost-has-session-spoofing-due-to-lack-of-single-use","title":"Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement","severity":"medium","exploited":false,"published_at":"2026-04-17T15:31:17+00:00","url":"https://junglewise.ai/threats/cve-2026-3590-mattermost-has-session-spoofing-due-to-lack-of-single-use"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}