CVEFinder.io

CVE-2026-6347

⚠️ high
πŸ” Scan for this CVE
Summary

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a support packet to obtain TURN server credentials via the plaintext values present in the exported plugin configuration.. Mattermost Advisory ID: MMSA-2026-00605

CVSS Score
7.6
High
EPSS Score
0.1
Exploit Probability
Published Date
2026-05-18
First Seen: 2026-05-19
πŸ“Š Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 69.4% of all 326,604 vulnerabilities in our database.

#100,092
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: May 18, 2026
πŸ” Exploitation Status
None
No known exploits
βš™οΈ Automatable
NO
Requires human interaction
πŸ’₯ Technical Impact
Partial
Limited system impact
πŸ† Discovered By
Edgar Bellot MicΓ³
SSVC data provided by CISA
Last Modified 2026-05-18
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
CWE IDs (Weakness Types)

πŸ“¦ Affected Products 3

πŸ”— References 1

πŸ”— Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-4915 πŸ”Ά medium 6.5 0.1 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil element... 2026-05-25
CVE-2026-3473 πŸ”Ά medium 5.9 0.0 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file owne... 2026-05-22
CVE-2026-3636 πŸ”Ά medium 4.3 0.0 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team memb... 2026-05-22
CVE-2026-4635 πŸ”Ά medium 6.5 0.0 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channe... 2026-05-22
CVE-2026-4646 πŸ”Ά medium 4.3 0.1 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supp... 2026-05-22
CVE-2026-5308 πŸ”Ά medium 4.9 0.1 Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request bo... 2026-05-22
These CVEs affect the same products