CVE-2024-43813: Mattermost

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel inside any team as read for any user.

Affected products

  • Mattermost Mattermost: from 9.5.0, before 9.5.8 (fixed in 9.5.8); from 9.10.0, before 9.10.1 (fixed in 9.10.1)

Published 2024-08-22. Last modified 2026-06-17.