Our takeCCCS updated its Mattermost advisory (AV26-828) covering versions up to 10.11.21, 11.7.6 and 11.8.3. Update if you self-host; teams on Mattermost's hosted cloud get patched upstream and can skip this one.Cyber Resilience desk
Sources (7)
What this means for you — Security leader:Update Mattermost servers to 10.11.22, 11.7.7 or 11.8.4 (or later). Review the CCCS advisory for exact affected versions and patch guidance.
What this means for you — Lean IT orgs:If you run your own Mattermost server, update it today to the latest version. Most teams using the hosted Mattermost service can ignore this.
What this means for you — MSP:Check every client running self-hosted Mattermost; update to 10.11.22+, 11.7.7+ or 11.8.4+ immediately. Confirm whether any use the hosted service (unaffected).
What this means for you — Researcher:CCCS published AV26-828 covering multiple vulnerabilities in Mattermost ≤10.11.21, ≤11.7.6 and ≤11.8.3. Apply updates per the linked advisory.