CVE-2026-2578: Mattermost Server

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which allows channel members to access unrevealed burn-on-read message contents via the WebSocket post deletion event.. Mattermost Advisory ID: MMSA-2026-00579

Affected products

  • Mattermost Mattermost Server: from 11.3.0, before 11.3.1 (fixed in 11.3.1)

Published 2026-03-16. Last modified 2026-06-17.