CVE-2019-20869: Mattermost Server

Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue was discovered in Mattermost Server before 5.10.0, 5.9.1, 5.8.2, and 4.10.9. A non-member could change the Update/Patch Channel endpoint for a private channel.

Affected products

  • Mattermost Mattermost Server: before 4.10.9 (fixed in 4.10.9); from 5.7.0, before 5.7.3 (fixed in 5.7.3); from 5.8.0, before 5.8.2 (fixed in 5.8.2); from 5.9.0, before 5.9.1 (fixed in 5.9.1); version 5.10.0 only

Published 2020-06-19. Last modified 2026-06-17.