Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-28759

3 месяца назад

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious remote cluster to remove any user from any channel, including private channels, via crafted membership sync messages targeting channels the remote cluster is not authorized to access. Mattermost Advisory ID: MMSA-2026-00576

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2026-28759

3 месяца назад

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 1 ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-8h9w-w78c-vvr3

3 месяца назад

Mattermost does not verify remote cluster channel access when processing shared channel membership removals

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-28759

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate that a remote cluster has access to a channel before processing membership removal requests during shared channel membership sync, which allows a malicious remote cluster to remove any user from any channel, including private channels, via crafted membership sync messages targeting channels the remote cluster is not authorized to access. Mattermost Advisory ID: MMSA-2026-00576

CVSS3: 4.3
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-28759

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 1 ...

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-8h9w-w78c-vvr3

Mattermost does not verify remote cluster channel access when processing shared channel membership removals

CVSS3: 4.3
0%
Низкий
3 месяца назад

Уязвимостей на страницу