CVE-2023-2787: Mattermost

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Mattermost fails to check channel membership when accessing message threads, allowing an attacker to access arbitrary posts by using the message threads API.

Affected products

  • Mattermost Mattermost: from 7.1.0, up to and including 7.1.9; from 7.8.0, up to and including 7.8.4; from 7.9.0, up to and including 7.9.3; version 7.10.0 only

Published 2023-06-16. Last modified 2026-06-17.