CVE-2024-11599: Mattermost Server

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate email addresses which allows an unauthenticated user to bypass email domain restrictions via carefully crafted input on email registration.

Affected products

  • Mattermost Mattermost Server: from 9.5.0, before 9.5.12 (fixed in 9.5.12); from 9.11.0, before 9.11.4 (fixed in 9.11.4); from 10.0.0, before 10.0.2 (fixed in 10.0.2); from 10.1.0, before 10.1.2 (fixed in 10.1.2)

Published 2024-11-28. Last modified 2026-06-17.