# Multiple Vulnerabilities Patched in Mattermost

Published: 2026-05-19 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/011cb165-bf10-5c77-a13d-99f14b7eea11/multiple-vulnerabilities-patched-in-mattermost

> ANSSI advisory details several Mattermost Server and Desktop App vulnerabilities enabling privilege escalation and data compromise; patches available.

CERT-FR issued an advisory covering multiple vulnerabilities in Mattermost products, including the Desktop App (versions prior to 5.13.6 and prior to 6.2) and Mattermost Server (versions 10.11.x prior to 10.11.17, 11.5.x prior to 11.5.5, and 11.6.x prior to 11.6.2). The flaws can lead to privilege escalation, data confidentiality breaches, data integrity violations, and security policy bypass.

Seven CVEs are referenced (CVE-2026-3433, CVE-2026-6046, CVE-2026-6689, CVE-2026-6739, CVE-2026-6961, CVE-2026-7184, CVE-2026-7387), tied to two Mattermost security bulletins (MMSA-2026-00652 and MMSA-2026-00662) published in May 2026. No active exploitation is reported; this is a standard vendor disclosure with patches available. Organizations using affected Mattermost versions should apply the vendor-provided fixes referenced in the security bulletins.

## Mentioned in this report

- Vulnerabilities: CVE-2026-3433, CVE-2026-6046, CVE-2026-6689, CVE-2026-6739, CVE-2026-6961, CVE-2026-7184, CVE-2026-7387

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0610

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/011cb165-bf10-5c77-a13d-99f14b7eea11/multiple-vulnerabilities-patched-in-mattermost.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
