Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data Retention Policy permission to obtain a private team's secret invite_id and email, and use it to join the team without authorization, via GET /api/v4/data_retention/policies/{policy_id}/teams.. Mattermost Advisory ID: MMSA-2026-00702 Join the discussion | GCVE Database | 09/15/2026, 00:31:13 UTC Added: 09/15/2026, 01:37:36 UTC |
0 Mattermost, Inc. heeft kwetsbaarheden verholpen in Mattermost versies 10.11.x, 11.7.x en 11.8.x, inclusief de GitLab plugin tot versie 11.8. Join the discussion | GCVE Database | 08/19/2026, 06:34:05 UTC Added: 08/18/2026, 00:42:28 UTC |
Mattermost versions 11.7.x up to 11.7.6, 10.11.x up to 10.11.21, and 11.8.x up to 11.8.3 contain a vulnerability where the PermissionManageBoardRoles permission is not enforced on the channelId field of the batch endpoint. This flaw allows an authenticated board editor to relink any board they can edit to an arbitrary channel by sending a crafted PATCH request. The vulnerability has a moderate severity with a CVSS score of 6.5. Join the discussion | GCVE Database | 08/18/2026, 00:30:36 UTC Added: 08/18/2026, 00:42:16 UTC |
Mattermost versions 10.11.x up to 10.11.20 and 11.7.x up to 11.7.5 fail to remove thread membership records when a user leaves or is removed from a team. This flaw allows a user who was previously removed but later re-invited to the team to access private channel thread root post content and metadata through the team threads API. The vulnerability has a low severity score and does not impact integrity or availability. Join the discussion | GCVE Database | 08/18/2026, 00:30:36 UTC Added: 08/18/2026, 00:42:16 UTC |
Mattermost versions 11.7.x up to 11.7.6, 10.11.x up to 10.11.21, and 11.8.x up to 11.8.3 contain a vulnerability where the BoardMember.Scheme fields are not properly validated server-side during insert and archive-import operations. This flaw allows a board editor or any non-guest team member to escalate privileges by granting board admin rights to arbitrary users via specific API endpoints. Join the discussion | GCVE Database | 08/18/2026, 00:30:36 UTC Added: 08/18/2026, 00:42:13 UTC |
Mattermost versions 11.7.x up to 11.7.6 and 10.11.x up to 10.11.21 contain a vulnerability where run-state validation is not enforced on write operations for finished playbook runs. This flaw allows participants of a run to modify certain aspects such as status, checklists, retrospective content, ownership, and participants on completed runs via REST and GraphQL API requests. Join the discussion | GCVE Database | 08/17/2026, 15:30:40 UTC Added: 08/17/2026, 16:13:59 UTC |
Mattermost versions 11.7.x up to 11.7.6 and 10.11.x up to 10.11.21 contain a vulnerability that allows guest users to be escalated to Board Admin privileges during the import of a crafted board archive file. This privilege escalation occurs because the software fails to properly restrict guest user permissions in this context. The issue is identified as CVE-2026-16044 and has a medium severity rating with a CVSS score of 5.4. Join the discussion | GCVE Database | 08/17/2026, 15:30:40 UTC Added: 08/17/2026, 16:13:57 UTC |
Mattermost versions 11.7.x up to 11.7.6, 10.11.x up to 10.11.21, and 11.8.x up to 11.8.3 contain a vulnerability where the software fails to verify that users have read access to a channel before linking a board to it. This flaw allows an authenticated attacker to discover membership of private channels within the same team by manipulating boards with arbitrary channel IDs. Join the discussion | GCVE Database | 08/17/2026, 15:30:40 UTC Added: 08/17/2026, 16:13:57 UTC |
Mattermost versions 11.7.x up to 11.7.6 and 10.11.x up to 10.11.21 contain a vulnerability where OAuth deauthorization and personal access token management endpoints are not properly restricted to direct user sessions. This flaw allows an OAuth app with a delegated user token to revoke the user's authorizations or tokens for other integrations via account-management endpoints. The issue is tracked as CVE-2026-16045 and has a medium severity rating. Join the discussion | GCVE Database | 08/17/2026, 15:30:40 UTC Added: 08/17/2026, 16:13:57 UTC |
Mattermost versions 11.7.x up to 11.7.6, 10.11.x up to 10.11.21, and 11.8.x up to 11.8.3 contain a vulnerability where the system fails to properly reconcile SchemeAdmin flags with a user's current role. This flaw allows users who have been demoted to System Guest to retain Board Admin privileges and perform administrative actions through the Boards REST API or UI. Join the discussion | GCVE Database | 08/17/2026, 15:30:40 UTC Added: 08/17/2026, 16:13:54 UTC |
Showing 1 to 10 of 19 results