CVE-2026-3495: Unescaped variables during error page composition
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some malicious code via injecting some JS as part of those values.. Mattermost Advisory ID: MMSA-2026-00622
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3495?
CVE-2026-3495 is considered a medium severity vulnerability affecting specific versions of Mattermost.
How do I fix CVE-2026-3495?
To fix CVE-2026-3495, upgrade Mattermost to version 11.5.2 or later for the 11.5.x series, or to version 10.11.14 or later for the 10.11.x series.
What versions of Mattermost are affected by CVE-2026-3495?
CVE-2026-3495 affects Mattermost versions 11.5.0 to 11.5.1 and 10.11.0 to 10.11.13.
What types of attacks can CVE-2026-3495 potentially facilitate?
CVE-2026-3495 could allow an attacker to execute arbitrary code if they can manipulate error page variables.
Who is at risk due to CVE-2026-3495?
Users of Mattermost who have access to edit site configuration settings are at risk due to CVE-2026-3495.