VORANT. Threat Intelligence Sign in Get the full feed

Multiple Vulnerabilities Patched in Mattermost

routine vulnerability technology

ANSSI advisory details several Mattermost Server and Desktop App vulnerabilities enabling privilege escalation and data compromise; patches available.

CERT-FR issued an advisory covering multiple vulnerabilities in Mattermost products, including the Desktop App (versions prior to 5.13.6 and prior to 6.2) and Mattermost Server (versions 10.11.x prior to 10.11.17, 11.5.x prior to 11.5.5, and 11.6.x prior to 11.6.2). The flaws can lead to privilege escalation, data confidentiality breaches, data integrity violations, and security policy bypass.

Seven CVEs are referenced (CVE-2026-3433, CVE-2026-6046, CVE-2026-6689, CVE-2026-6739, CVE-2026-6961, CVE-2026-7184, CVE-2026-7387), tied to two Mattermost security bulletins (MMSA-2026-00652 and MMSA-2026-00662) published in May 2026. No active exploitation is reported; this is a standard vendor disclosure with patches available. Organizations using affected Mattermost versions should apply the vendor-provided fixes referenced in the security bulletins.

Mentioned in this report

Vulnerabilities CVE-2026-3433CVE-2026-6046CVE-2026-6689CVE-2026-6739CVE-2026-6961CVE-2026-7184CVE-2026-7387

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0610

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free