By vendor

Mattermost vulnerabilities

Known CVEs affecting Mattermost products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-3433MEDIUM 4.3

    Mattermost's websocket service inadvertently broadcasts permission change notifications to all authenticated users, including guest-level accounts, even when those users lack membership in the affected team or channel. An attacker with guest credentials can observe role and permission updates for private teams they should have no visibility into, revealing information about organizational access controls. This is a confidentiality issue requiring authentication to exploit but affecting teams that rely on Mattermost's role-based access controls to maintain information barriers between guest and member populations.