Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY457 SECURITY RECORDS

Mattermost

Mattermost

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This CVE identity is linked to the Lifecycle record Mattermost. Use that record for publisher support phases and retirement dates.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-9571 13 Jul 2026 11.7.0 ≤ 11.7.2; 11.6.0 ≤ 11.6.4; 10.11.0 ≤ 10.11.19 11.8.0; 11.7.3; 11.6.5; 10.11.20 Update reference ↗
CVE-2026-4339 26 Jun 2026 10.11.0 ≤ 10.11.18; 11.6.0 ≤ 11.6.3; 11.5.0 ≤ 11.5.6 11.7.0; 10.11.19; 11.6.4; 11.5.7 Update reference ↗
CVE-2026-9699 26 Jun 2026 ≤ 10.18.11; ≤ 11.3.6; ≤ 11.6.5 11.7.0; 10.11.19; 11.6.4; 11.5.7 Update reference ↗
CVE-2026-3472 26 Jun 2026 10.11.0 ≤ 10.11.18; 11.6.0 ≤ 11.6.3; 11.5.0 ≤ 11.5.6 11.7.0; 10.11.19; 11.6.4; 11.5.7 Update reference ↗
CVE-2026-8823 22 Jun 2026 11.7.0 ≤ 11.7.0; 10.11.0 ≤ 10.11.17 11.8.0; 11.7.1; 10.11.18 Update reference ↗
CVE-2026-6062 22 Jun 2026 11.7.0 ≤ 11.7.0; 11.6.0 ≤ 11.6.2; 11.5.0 ≤ 11.5.5; 10.11.0 ≤ 10.11.17 11.8.0; 11.7.1; 11.6.3; 11.5.6; 10.11.18 Update reference ↗
CVE-2026-6673 22 Jun 2026 11.7.0 ≤ 11.7.0; 11.6.0 ≤ 11.6.2; 11.5.0 ≤ 11.5.5; 10.11.0 ≤ 10.11.17 11.8.0; 11.7.1; 11.6.3; 11.5.6; 10.11.18 Update reference ↗
CVE-2026-8074 22 Jun 2026 11.7.0 ≤ 11.7.0; 10.11.0 ≤ 10.11.17 11.8.0; 11.7.1; 10.11.18 Update reference ↗
CVE-2026-9162 22 Jun 2026 11.7.0 ≤ 11.7.0; 11.6.0 ≤ 11.6.2; 11.5.0 ≤ 11.5.5; 10.11.0 ≤ 10.11.17 11.8.0; 11.7.1; 11.6.3; 11.5.6; 10.11.18 Update reference ↗
CVE-2026-5139 22 Jun 2026 11.7.0 ≤ 11.7.0; 11.6.0 ≤ 11.6.2; 11.5.0 ≤ 11.5.5; 10.11.0 ≤ 10.11.17 11.8.0; 11.7.1; 11.6.3; 11.5.6; 10.11.18 Update reference ↗
CVE-2026-8683 15 Jun 2026 ≤ 5.5.13 6.2.0; 5.13.6.0 Update reference ↗
CVE-2026-6517 15 Jun 2026 ≤ 5.5.13 6.2.0; 5.13.6.0 Update reference ↗
CVE-2026-6961 12 Jun 2026 11.6.0 ≤ 11.6.1; 11.5.0 ≤ 11.5.4; 10.11.0 ≤ 10.11.15; 10.11.0 ≤ 10.11.16 11.7.0; 11.6.2; 11.5.5; 10.11.16; 10.11.17 Update reference ↗
CVE-2026-7387 12 Jun 2026 11.6.0 ≤ 11.6.1; 11.5.0 ≤ 11.5.4; 10.11.0 ≤ 10.11.15; 10.11.0 ≤ 10.11.16 11.7.0; 11.6.2; 11.5.5; 10.11.16; 10.11.17 Update reference ↗
CVE-2026-6046 12 Jun 2026 11.6.0 ≤ 11.6.1; 11.5.0 ≤ 11.5.4; 10.11.0 ≤ 10.11.15; 10.11.0 ≤ 10.11.16 11.7.0; 11.6.2; 11.5.5; 10.11.16; 10.11.17 Update reference ↗
CVE-2026-6689 12 Jun 2026 11.6.0 ≤ 11.6.1; 11.5.0 ≤ 11.5.4; 10.11.0 ≤ 10.11.15; 10.11.0 ≤ 10.11.16 11.7.0; 11.6.2; 11.5.5; 10.11.16; 10.11.17 Update reference ↗
CVE-2026-7184 12 Jun 2026 11.6.0 ≤ 11.6.1; 11.5.0 ≤ 11.5.4; 10.11.0 ≤ 10.11.15 11.7.0; 11.6.2; 11.5.5; 10.11.17 Update reference ↗
CVE-2026-6739 12 Jun 2026 11.6.0 ≤ 11.6.1; 11.5.0 ≤ 11.5.4; 10.11.0 ≤ 10.11.15; 10.11.0 ≤ 10.11.16 11.7.0; 11.6.2; 11.5.5; 10.11.16; 10.11.17 Update reference ↗
CVE-2026-3433 12 Jun 2026 11.6.0 ≤ 11.6.1; 11.5.0 ≤ 11.5.4; 10.11.0 ≤ 10.11.15; 10.11.0 ≤ 10.11.16 11.7.0; 11.6.2; 11.5.5; 10.11.16; 10.11.17 Update reference ↗
CVE-2026-6957 27 May 2026 ≤ 1.1.5 .0 Update reference ↗
CVE-2026-4915 25 May 2026 11.6.0 ≤ 11.6.0; 11.5.0 ≤ 11.5.3; 11.4.0 ≤ 11.4.4; 10.11.0 ≤ 10.11.14 11.7.0; 11.6.1; 11.5.4; 11.4.5; 10.11.15 Update reference ↗
CVE-2026-28735 22 May 2026 11.6.0 ≤ 11.6.0; 11.5.0 ≤ 11.5.3; 11.4.0 ≤ 11.4.4; 10.11.0 ≤ 10.11.14 11.7.0; 11.6.1; 11.5.4; 11.4.5; 10.11.15 Update reference ↗
CVE-2026-4635 22 May 2026 11.6.0 ≤ 11.6.0; 11.5.0 ≤ 11.5.3; 11.4.0 ≤ 11.4.4; 10.11.0 ≤ 10.11.14 11.7.0; 11.6.1; 11.5.4; 11.4.5; 10.11.15 Update reference ↗
CVE-2026-3473 22 May 2026 11.6.0 ≤ 11.6.0; 11.5.0 ≤ 11.5.3; 11.4.0 ≤ 11.4.4; 10.11.0 ≤ 10.11.14 11.7.0; 11.6.1; 11.5.4; 11.4.5; 10.11.15 Update reference ↗
CVE-2026-4646 22 May 2026 11.6.0 ≤ 11.6.0; 11.5.0 ≤ 11.5.3; 11.4.0 ≤ 11.4.4; 10.11.0 ≤ 10.11.14 11.7.0; 11.6.1; 11.5.4; 11.4.5; 10.11.15 Update reference ↗
CVE-2026-3636 22 May 2026 11.6.0 ≤ 11.6.0; 11.5.0 ≤ 11.5.3; 11.4.0 ≤ 11.4.4; 10.11.0 ≤ 10.11.14 11.7.0; 11.6.1; 11.5.4; 11.4.5; 10.11.15 Update reference ↗
CVE-2026-5740 22 May 2026 11.6.0 ≤ 11.6.0; 11.5.0 ≤ 11.5.3; 11.4.0 ≤ 11.4.4; 10.11.0 ≤ 10.11.14 11.7.0; 11.6.1; 11.5.4; 11.4.5; 10.11.15 Update reference ↗
CVE-2026-5308 22 May 2026 11.6.0 ≤ 11.6.0; 11.5.0 ≤ 11.5.3; 11.4.0 ≤ 11.4.4; 10.11.0 ≤ 10.11.14 11.7.0; 11.6.1; 11.5.4; 11.4.5; 10.11.15 Update reference ↗
CVE-2026-5755 22 May 2026 11.6.0 ≤ 11.6.0; 11.5.0 ≤ 11.5.2; 11.5.0 ≤ 11.5.3; 11.4.0 ≤ 11.4.4; 10.11.0 ≤ 10.11.14 11.7.0; 11.6.1; 11.5.3; 11.5.4; 11.4.5; 10.11.15 Update reference ↗
CVE-2026-22880 21 May 2026 ≤ 2.0.37; ≤ 11.0.4; ≤ 11.1.3; ≤ 11.3.2; ≤ 10.11.11 2.38.0; 11.5.0; 2.37.1.0; 11.4.1; 11.3.2; 11.2.4; 10.11.12 Update reference ↗
CVE-2026-4858 21 May 2026 11.6.0 ≤ 11.6.0; 11.5.0 ≤ 11.5.3; 11.4.0 ≤ 11.4.4; 10.11.0 ≤ 10.11.14 11.7.0; 11.6.1; 11.5.4; 11.4.5; 10.11.15 Update reference ↗
CVE-2026-4055 21 May 2026 11.5.0 ≤ 11.5.1 11.6.0; 11.5.2; 10.11.14; 11.4.4 Update reference ↗
CVE-2026-3471 18 May 2026 ≤ 6.0.1; ≤ 5.4.13 6.2.0; 6.1.1.0; 5.13.5.0 Update reference ↗
CVE-2026-4643 18 May 2026 ≤ 6.0.1; ≤ 5.4.13 6.2.0; 6.1.1.0; 5.13.5.0 Update reference ↗
CVE-2026-6333 18 May 2026 11.5.0 ≤ 11.5.1; 10.11.0 ≤ 10.11.13 11.6.0; 11.5.2; 10.11.14 Update reference ↗
CVE-2026-6345 18 May 2026 11.5.0 ≤ 11.5.1; 10.11.0 ≤ 10.11.13; 11.4.0 ≤ 11.4.3 11.6.0; 11.5.2; 10.11.14; 11.4.4 Update reference ↗
CVE-2026-6346 18 May 2026 11.5.0 ≤ 11.5.1; 10.11.0 ≤ 10.11.13; 11.4.0 ≤ 11.4.3 11.6.0; 11.5.2; 10.11.14; 11.4.4 Update reference ↗
CVE-2026-28732 18 May 2026 11.5.0 ≤ 11.5.1; 10.11.0 ≤ 10.11.13; 11.4.0 ≤ 11.4.3 11.6.0; 11.5.2; 10.11.14; 11.4.4 Update reference ↗
CVE-2026-6343 18 May 2026 11.5.0 ≤ 11.5.1; 10.11.0 ≤ 10.11.13; 11.4.0 ≤ 11.4.3 11.6.0; 11.5.2; 10.11.14; 11.4.4 Update reference ↗
CVE-2026-6347 18 May 2026 11.5.0 ≤ 11.5.1; 10.11.0 ≤ 10.11.13; 11.4.0 ≤ 11.4.3 11.6.0; 11.5.2; 10.11.14; 11.4.4 Update reference ↗
CVE-2026-5163 18 May 2026 11.5.0 ≤ 11.5.1 11.6.0; 11.5.2 Update reference ↗
CVE-2026-3117 18 May 2026 ≤ 11.1.5; ≤ 10.13.11; ≤ 11.3.4 11.6.0; 11.5.2; 10.11.14; 11.4.4 Update reference ↗
CVE-2026-4286 18 May 2026 11.5.0 ≤ 11.5.1; 10.11.0 ≤ 10.11.13 11.6.0; 11.5.2; 10.11.14 Update reference ↗
CVE-2026-6339 18 May 2026 11.5.0 ≤ 11.5.1; 11.4.0 ≤ 11.4.3 11.6.0; 11.5.2; 11.4.4 Update reference ↗
CVE-2026-6340 18 May 2026 11.5.0 ≤ 11.5.1; 10.11.0 ≤ 10.11.13; 11.4.0 ≤ 11.4.3 11.6.0; 11.5.2; 10.11.14; 11.4.4 Update reference ↗
CVE-2026-6341 18 May 2026 ≤ 11.1.5; ≤ 10.13.11; ≤ 11.3.4 11.6.0; 11.5.2; 10.11.14; 11.4.4 Update reference ↗
CVE-2026-6342 18 May 2026 ≤ 11.1.5; ≤ 10.13.11; ≤ 11.3.4 11.6.0; 11.5.2; 10.11.14; 11.4.4 Update reference ↗
CVE-2026-3495 18 May 2026 11.5.0 ≤ 11.5.1; 10.11.0 ≤ 10.11.13 11.6.0; 11.5.2; 10.11.14 Update reference ↗
CVE-2026-4273 18 May 2026 11.5.0 ≤ 11.5.1; 10.11.0 ≤ 10.11.13 11.6.0; 11.5.2; 10.11.14 Update reference ↗
CVE-2026-3637 18 May 2026 11.5.0 ≤ 11.5.1; 10.11.0 ≤ 10.11.13; 11.4.0 ≤ 11.4.3 11.6.0; 11.5.2; 10.11.14; 11.4.4 Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.