Multiple Vulnerabilities Patched in Mattermost
ANSSI advisory details several Mattermost Server and Desktop App vulnerabilities enabling privilege escalation and data compromise; patches available.
CERT-FR issued an advisory covering multiple vulnerabilities in Mattermost products, including the Desktop App (versions prior to 5.13.6 and prior to 6.2) and Mattermost Server (versions 10.11.x prior to 10.11.17, 11.5.x prior to 11.5.5, and 11.6.x prior to 11.6.2). The flaws can lead to privilege escalation, data confidentiality breaches, data integrity violations, and security policy bypass.
Seven CVEs are referenced (CVE-2026-3433, CVE-2026-6046, CVE-2026-6689, CVE-2026-6739, CVE-2026-6961, CVE-2026-7184, CVE-2026-7387), tied to two Mattermost security bulletins (MMSA-2026-00652 and MMSA-2026-00662) published in May 2026. No active exploitation is reported; this is a standard vendor disclosure with patches available. Organizations using affected Mattermost versions should apply the vendor-provided fixes referenced in the security bulletins.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0610
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free