# Mattermost patches multiple unspecified vulnerabilities

Published: 2026-05-22 · Severity: medium
Canonical: https://vorant.io/reports/5a20c066-9282-5995-a70c-0f13570462b7/mattermost-patches-multiple-unspecified-vulnerabilities

> Mattermost released patches for multiple unspecified vulnerabilities affecting Desktop App and Server versions, with details not yet publicly disclosed.

The French CERT (CERT-FR) has issued an advisory regarding multiple security vulnerabilities discovered in Mattermost products. The affected products include Mattermost Desktop App versions 6.x prior to 6.2 and versions prior to 5.13.6, as well as Mattermost Server across multiple version branches: 10.11.x prior to 10.11.18, 11.5.x prior to 11.5.6, 11.6.x prior to 11.6.3, and 11.7.x prior to 11.7.1.

The vendor has not publicly specified the nature or severity of these vulnerabilities in the available documentation. Seven separate security bulletins (MMSA-2026-00644, 00650, 00651, 00654, 00664, 00667, and 00669) were released on May 21, 2026, suggesting multiple distinct issues requiring remediation. At least one vulnerability has been assigned CVE-2026-6517, though technical details remain undisclosed.

Organizations running affected Mattermost deployments should consult the vendor security bulletins and apply the available patches promptly. The lack of public technical details suggests potential coordinated disclosure or embargo periods may be in effect.

## Mentioned in this report

- Vulnerabilities: CVE-2026-6517

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0632

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5a20c066-9282-5995-a70c-0f13570462b7/mattermost-patches-multiple-unspecified-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
