
CVE-2026-2457 Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to sanitize client-supplied post metadata which allows an authenticated attacker to spo… https://www.cve.org/CVERecord?id=CVE-2026-2457
Post summary
The post discloses that Mattermost versions up to 11.3.0, 11.2.2, and 10.11.10 have a metadata sanitization flaw allowing authenticated attackers to exploit the system, but it offers no PoC, exploit code, or patch information.
