CVE-2023-2515: Mattermost Server

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Mattermost fails to restrict a user with permissions to edit other users and to create personal access tokens from elevating their privileges to system admin

Affected products

  • Mattermost Mattermost Server: before 7.1.8 (fixed in 7.1.8); from 7.2.0, before 7.7.4 (fixed in 7.7.4); from 7.8.0, before 7.8.3 (fixed in 7.8.3); from 7.9.0, before 7.9.2 (fixed in 7.9.2)

Published 2023-05-12. Last modified 2026-06-17.