Multiple vulnerabilities in Mattermost products (May 19, 2026)
Multiple vulnerabilities have been discovered in Mattermost products. Some of them allow an attacker to cause privilege escalation, data confidentiality breach and data integrity breach.
CSIRTS triage
- What
- Multiple vulnerabilities in Mattermost products allow attackers to escalate privileges, breach data confidentiality, and compromise data integrity.
- Who is affected
- All Mattermost product deployments are affected; specific versions are not stated.
- Urgency
- High urgency; privilege escalation and data breach capabilities present serious risk even without active exploitation.
- Action
- Check Mattermost security advisory page for affected versions and apply patches or updates immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Mattermost
Get an email when a new Mattermost advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0610/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-66890.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-67390.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-71840.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-73870.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-34330.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-60460.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-69610.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-6689 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6739 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7184 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-7387 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-3433 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6046 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6961 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Mattermost products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMultiple vulnerabilities in Mattermost products (August 14, 2026)cert-fr-avis · 2026-08-14
- unknownMultiple vulnerabilities in Mattermost products (June 15, 2026)cert-fr-avis · 2026-06-15
- unknownMultiple vulnerabilities in Mattermost products (May 29, 2026)cert-fr-avis · 2026-05-29
- unknownMultiple vulnerabilities in Mattermost products (May 22, 2026)cert-fr-avis · 2026-05-22
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Mattermost products (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Ubuntu Linux kernel (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Red Hat Linux kernel (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Debian Linux kernel (August 14, 2026)2026-08-14
- unknownVulnerability in Sophos products (August 14, 2026)2026-08-14