Mattermost doesn't prevent disclosure of created user password
Moderate severity
GitHub Reviewed
Published
May 18, 2026
to the GitHub Advisory Database
•
Updated Jun 1, 2026
Package
Affected versions
< 5.3.2-0.20260311102650-3057ae7e83e9
Patched versions
5.3.2-0.20260311102650-3057ae7e83e9
>= 11.5.0, < 11.5.2
>= 10.11.0, < 10.11.14
>= 11.4.0, < 11.4.4
< 8.0.0-20260311102650-3057ae7e83e9
11.5.2
10.11.14
11.4.4
8.0.0-20260311102650-3057ae7e83e9
Description
Published by the National Vulnerability Database
May 18, 2026
Published to the GitHub Advisory Database
May 18, 2026
Reviewed
Jun 1, 2026
Last updated
Jun 1, 2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 doesn't prevent disclosure of created user password which allows a malicious attacker to impersonate a user via the use of some of those passwords.. Mattermost Advisory ID: MMSA-2026-00614
References