# CERT-FR flags multiple Mattermost Server flaws

Published: 2026-09-16 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/547a716d-9762-5a7d-8c9e-e707a780939a/cert-fr-flags-multiple-mattermost-server-flaws

> CERT-FR advisory covers multiple Mattermost Server vulnerabilities allowing data confidentiality breaches; patches available.

CERT-FR published an advisory summarizing multiple vulnerabilities in Mattermost Server, an open-source collaboration platform. The flaws, disclosed across numerous Mattermost security bulletins (MMSA-2026 series) dated September 2026, affect several release branches: 11.10.x prior to 11.10.2, 11.7.x prior to 11.7.11, 11.8.x prior to 11.8.6, 11.9.x prior to 11.9.2, and all versions prior to 10.11.23. The vendor has not fully specified the nature of all issues, but CERT-FR characterizes the impact as a breach of data confidentiality along with an unspecified security issue.

One CVE identifier is referenced (CVE-2026-91181), though details on exploitability and technical mechanics are not provided in this advisory beyond the vendor bulletins. No indication of active exploitation in the wild is mentioned. Defenders running Mattermost Server should consult the linked vendor security bulletins for full technical details and apply the corrected versions (11.10.2, 11.7.11, 11.8.6, 11.9.2, or 10.11.23 and later) as soon as possible, prioritizing confidentiality-impacting instances especially where Mattermost is used for internal or sensitive communications.

## Mentioned in this report

- Vulnerabilities: CVE-2026-91181

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1190

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/547a716d-9762-5a7d-8c9e-e707a780939a/cert-fr-flags-multiple-mattermost-server-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
