Количество 3
Количество 3
CVE-2026-9597
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681
CVE-2026-9597
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify ...
GHSA-42ff-p8fr-h5jr
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-9597 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681 | CVSS3: 5.4 | 0% Низкий | 19 дней назад | |
CVE-2026-9597 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify ... | CVSS3: 5.4 | 0% Низкий | 19 дней назад | |
GHSA-42ff-p8fr-h5jr Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory ID: MMSA-2026-00681 | CVSS3: 5.4 | 0% Низкий | 19 дней назад |
Уязвимостей на страницу