CVE-2019-20878: Mattermost Server

Medium severity, CVSS 4.3. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. Changes, within the application, to e-mail addresses are mishandled.

Affected products

  • Mattermost Mattermost Server: before 4.10.8 (fixed in 4.10.8); from 5.7.0, before 5.7.3 (fixed in 5.7.3); from 5.8.0, before 5.8.1 (fixed in 5.8.1); version 5.9.0 only

Published 2020-06-19. Last modified 2026-06-17.