CVE-2026-3495 LOW

CVE-2026-3495: Unescaped variables during error page composition

Vendor Mattermost
Product Mattermost
Weakness CWE-79 · XSS
Published May 18, 2026
Last update May 18, 2026

CVSS base score

3.8/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

What the vulnerability does

01Description

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some malicious code via injecting some JS as part of those values.. Mattermost Advisory ID: MMSA-2026-00622

Key dates

02Disclosure timeline

May 18, 2026 CVE published
May 18, 2026 Record updated