VORANT. Threat Intelligence Sign in Get the full feed

Mattermost patches multiple unspecified vulnerabilities

medium vulnerability

Mattermost released patches for multiple unspecified vulnerabilities affecting Desktop App and Server versions, with details not yet publicly disclosed.

The French CERT (CERT-FR) has issued an advisory regarding multiple security vulnerabilities discovered in Mattermost products. The affected products include Mattermost Desktop App versions 6.x prior to 6.2 and versions prior to 5.13.6, as well as Mattermost Server across multiple version branches: 10.11.x prior to 10.11.18, 11.5.x prior to 11.5.6, 11.6.x prior to 11.6.3, and 11.7.x prior to 11.7.1.

The vendor has not publicly specified the nature or severity of these vulnerabilities in the available documentation. Seven separate security bulletins (MMSA-2026-00644, 00650, 00651, 00654, 00664, 00667, and 00669) were released on May 21, 2026, suggesting multiple distinct issues requiring remediation. At least one vulnerability has been assigned CVE-2026-6517, though technical details remain undisclosed.

Organizations running affected Mattermost deployments should consult the vendor security bulletins and apply the available patches promptly. The lack of public technical details suggests potential coordinated disclosure or embargo periods may be in effect.

Mentioned in this report

Vulnerabilities CVE-2026-6517

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0632

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free