<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Mattermost</title><description>Mattermost is an open-source, self-hosted messaging and collaboration platform used in security operations, incident response, and regulated industries. CVEs here cover authentication, authorization, and data-handling flaws in the server, client, and integrated plugins. Combined article + CVE feed for the Mattermost beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>Mattermost CVE-2026-14344: Board Permission Check Skipped</title><link>https://0daynews.com/articles/2026-09-17-mattermost-cve-2026-14344-board-auth-bypass/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-09-17-mattermost-cve-2026-14344-board-auth-bypass/</guid><description>CVE-2026-14344 lets any authenticated Mattermost user create boards regardless of role assignments. Four active release branches affected; upgrade per the security advisory.</description><pubDate>Thu, 17 Sep 2026 04:00:00 GMT</pubDate><category>Mattermost</category><category>article</category></item><item><title>CVE-2026-14344 — Mattermost Boards Board-Creation Permission Not Enforced</title><link>https://0daynews.com/cve/cve-2026-14344/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-14344/</guid><description>Mattermost through 11.9.0 fails to enforce board-creation permissions, letting any authenticated user create boards regardless of their role.</description><pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate><category>Mattermost</category><category>medium</category><category>cve</category></item></channel></rss>