CVE-2026-4339
Multiple vulnerabilities have been discovered in Mattermost products. They allow an attacker to cause data confidentiality breach, security policy bypass and an unspecified security issue by the editor.
CSIRTS triage
- What
- Multiple vulnerabilities in Mattermost products allow attackers to breach data confidentiality and bypass security policies through the editor.
- Who is affected
- All Mattermost product deployments are affected; specific versions are not stated.
- Urgency
- Moderate urgency; data confidentiality and policy bypass are serious but no active exploitation reported.
- Action
- Check Mattermost security advisory page for affected versions and apply available patches.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-4339
Get an email if CVE-2026-4339 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
Advisory coverage (2)
- mediumCVE-2026-4339: Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate at…nvd · 2026-06-26
- unknownMultiple vulnerabilities in Mattermost products (May 29, 2026)cert-fr-avis · 2026-05-29
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-4339)