4.3

CVSS3.1

CVE-2026-2458 - Unauthorized channel enumeration in private teams after member removal

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate team membership when searching channels which allows a removed team member to enumerate all public channels within a private team via the channel search API endpoint.. Mattermost Advisory ID: MMSA-…

πŸ“… Published: March 16, 2026, 11:27 a.m. πŸ”„ Last Modified: March 30, 2026, 7:02 a.m.

4.3

CVSS3.1

CVE-2026-2457 - WebSocket Message Spoofing via Permalink Embed Manipulation

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spoof permalink embeds impersonating other users via crafted PUT requests to the post update API endpoint.. Mattermost Advisory ID: MM…

πŸ“… Published: March 16, 2026, 11:20 a.m. πŸ”„ Last Modified: March 30, 2026, 7:02 a.m.

4.3

CVSS3.1

CVE-2026-2461 - Missing authorization check allows unauthorized modification of other users' comments on a board

Mattermost Plugins versions <=11.3 11.0.3 11.2.2 10.10.11.0 fail to implement authorisation checks on comment block modifications, which allows an authorised attacker with editor permission to modify comments created by other board members. Mattermost Advisory ID: MMSA-2025-00559

πŸ“… Published: March 16, 2026, 11:16 a.m. πŸ”„ Last Modified: March 30, 2026, 7:02 a.m.

4.3

CVSS3.1

CVE-2026-2463 - Unauthorized access to invite ID during team creation

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to filter invite IDs based on user permissions, which allows regular users to bypass access control restrictions and register unauthorized accounts via leaked invite IDs during team creation.. Mattermost Advisory ID: M…

πŸ“… Published: March 16, 2026, 11:13 a.m. πŸ”„ Last Modified: March 30, 2026, 7:02 a.m.

7.6

CVSS3.1

CVE-2026-2476 - MS Teams plugin sensitive config values not properly masked in support packets

Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606

πŸ“… Published: March 16, 2026, 11:11 a.m. πŸ”„ Last Modified: March 30, 2026, 7:02 a.m.

5.3

CVSS3.1

CVE-2026-2456 - Denial of Service via Unbounded Memory Allocation in Integration Actions

Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of responses from integration action endpoints, which allows an authenticated attacker to cause server memory exhaustion and denial of service via a malicious integration server that retur…

πŸ“… Published: March 16, 2026, 11:06 a.m. πŸ”„ Last Modified: March 30, 2026, 7:02 a.m.

6.9

CVSS4.0

CVE-2026-4235 - itsourcecode Online Enrollment System login.php sql injection

A weakness has been identified in itsourcecode Online Enrollment System 1.0. This issue affects some unknown processing of the file /sms/login.php. This manipulation of the argument user_email causes sql injection. The attack is possible to be carried out remotely. The exploit has been made availab…

πŸ“… Published: March 16, 2026, 11:02 a.m. πŸ”„ Last Modified: April 22, 2026, 9:32 p.m.

6

CVSS4.0

CVE-2025-15554 - Admin Passwords Cached by Browsers in Truesec LAPSWebUI

Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords.

πŸ“… Published: March 16, 2026, 10:46 a.m. πŸ”„ Last Modified: April 8, 2026, 8:01 p.m.

6

CVSS4.0

CVE-2025-15553 - Insecure Logout Functionality in Truesec LAPSWebUI

Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.

πŸ“… Published: March 16, 2026, 10:45 a.m. πŸ”„ Last Modified: April 20, 2026, 1:18 p.m.

6

CVSS4.0

CVE-2025-15552 - Long Session Lifetime in Truesec LAPSWebUI

Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.

πŸ“… Published: March 16, 2026, 10:44 a.m. πŸ”„ Last Modified: April 20, 2026, 1:29 p.m.
Total resulsts: 349182
Page 1099 of 34,919
Β« previous page Β» next page
Filters