StackRadar

CVE-2026-3115

Unscored

Advisory

Published 25 Jun 2026In the index since 6 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5
of 17,781 indexed, latest versions
Container images
5
deployed by those charts
Fix available
None
affected packages

Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server

Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 5 images.

Affected packageAffected versionsFixed inImages
github.com/mattermost/mattermost-server/v5golangv5.3.2-0.20210503144558-5c16de58a020, v5.3.2-0.20210524045451-a4f7df6f6e3c, v5.32.1, v5.34.2+1 moreno fix listed5
github.com/mattermost/mattermost-server/v6golangv6.7.2no fix listed1
OSV records
GO-2026-5512
Also known as
GHSA-mpc7-mm28-f6wq

Charts affected

5 by stars
ChartLatestAffected imagesRadar Score
focalboardgeek-cookbookVerified publisher4.4.21 of 1See more

focalboard geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-3115.

Container imageDigestPackageFixed in
mattermost/focalboard:0.9.031078df7a3c8
github.com/mattermost/mattermost-server/v5@v5.3.2-0.20210524045451-a4f7df6f6e3c
no fix listed

Open the chart page →

3,631
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-3115.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
github.com/mattermost/mattermost-server/v5@v5.39.3
github.com/mattermost/mattermost-server/v6@v6.7.2
no fix listed
no fix listed

Open the chart page →

5,074
focalboardmattermostVerified publisher0.5.01 of 1See more

focalboard mattermost 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-3115.

Container imageDigestPackageFixed in
mattermost/focalboard:0.6.7f2f987dada52
github.com/mattermost/mattermost-server/v5@v5.34.2
no fix listed

Open the chart page →

4,014
mattermost-chaos-enginemattermostVerified publisher0.2.01 of 1See more

mattermost-chaos-engine mattermost 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-3115.

Container imageDigestPackageFixed in
mattermost/mattermost-app-chaosengine:c153e436268954edd67
github.com/mattermost/mattermost-server/v5@v5.3.2-0.20210503144558-5c16de58a020
no fix listed

Open the chart page →

4,067
mindavphntom0.1.61 of 2See more

mindav phntom 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-3115.

Container imageDigestPackageFixed in
phntom/mindav:0.1.7-kix35695f546abbb
github.com/mattermost/mattermost-server/v5@v5.32.1
no fix listed

Open the chart page →

4,158

Container images carrying it

5 by charts deploying them

A fixed version is listed for 0 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mattermost/focalboard:0.9.031078df7a3c8
github.com/mattermost/mattermost-server/v5@v5.3.2-0.20210524045451-a4f7df6f6e3c
no fix listed
1
mattermost/focalboard:0.6.7f2f987dada52
github.com/mattermost/mattermost-server/v5@v5.34.2
no fix listed
1
mattermost/mattermost-app-chaosengine:c153e436268954edd67
github.com/mattermost/mattermost-server/v5@v5.3.2-0.20210503144558-5c16de58a020
no fix listed
1
phntom/mindav:0.1.7-kix35695f546abbb
github.com/mattermost/mattermost-server/v5@v5.32.1
no fix listed
1
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
github.com/mattermost/mattermost-server/v5@v5.39.3
github.com/mattermost/mattermost-server/v6@v6.7.2
no fix listed
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.