736,893 Mattermost Instances Publicly Indexed, Raising Self-Hosted Security Concerns
Cybersecurity search engine ZoomEye recorded 736,893 fingerprint matches for Mattermost, a self-hosted team collaboration platform, as of September 23, 2026. Mattermost is designed to keep organizational communications on internal infrastructure, making its widespread external discoverability a notable security concern. Many of these exposed instances may be running on port 8065, the platform's default, potentially without TLS encryption to protect messages and files in transit. Beyond chat content, the platform's webhooks, bots, and access tokens represent additional credential risks, especially if misconfigured or left unaudited. Security guidance emphasizes reviewing network placement, enforcing TLS and multi-factor authentication, and treating any credential shared in chat as potentially compromised.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in